PT-2022-3073 · Brocade · Brocade Fabric Os+1
Published
2022-06-22
·
Updated
2023-08-08
·
CVE-2022-28167
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Brocade SANnav versions prior to 2.2.0.2
Brocade SANnav versions prior to 2.1.1.8
Description
The issue is related to the storage of sensitive information in plain text. Specifically, the Brocade Fabric OS switch password is logged in plain text in the
asyncjobscheduler-manager.log file. This could allow an attacker to gain elevated privileges.Recommendations
For Brocade SANnav versions prior to 2.2.0.2, update to version 2.2.0.2 or later.
For Brocade SANnav versions prior to 2.1.1.8, update to version 2.1.1.8 or later.
As a temporary workaround, consider restricting access to the
asyncjobscheduler-manager.log file to minimize the risk of exploitation.Fix
Insufficiently Protected Credentials
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Brocade Fabric Os
Brocade Sannav