PT-2022-3073 · Brocade · Brocade Fabric Os+1

Published

2022-06-22

·

Updated

2023-08-08

·

CVE-2022-28167

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Brocade SANnav versions prior to 2.2.0.2 Brocade SANnav versions prior to 2.1.1.8
Description The issue is related to the storage of sensitive information in plain text. Specifically, the Brocade Fabric OS switch password is logged in plain text in the asyncjobscheduler-manager.log file. This could allow an attacker to gain elevated privileges.
Recommendations For Brocade SANnav versions prior to 2.2.0.2, update to version 2.2.0.2 or later. For Brocade SANnav versions prior to 2.1.1.8, update to version 2.1.1.8 or later. As a temporary workaround, consider restricting access to the asyncjobscheduler-manager.log file to minimize the risk of exploitation.

Fix

Insufficiently Protected Credentials

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

BDU:2022-03743
CVE-2022-28167

Affected Products

Brocade Fabric Os
Brocade Sannav