PT-2024-22492 · Brocade · Brocade Sannav

Pierre Barre

·

Published

2024-05-08

·

Updated

2024-05-09

·

CVE-2024-2860

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Brocade SANnav versions prior to 2.3.0a
Description The PostgreSQL implementation in Brocade SANnav is vulnerable to an incorrect local authentication flaw. An attacker accessing the VM where Brocade SANnav is installed can gain access to sensitive data inside the PostgreSQL database.
Recommendations For versions prior to 2.3.0a, update to version 2.3.0a or later to resolve the issue. As a temporary workaround, consider restricting access to the PostgreSQL database to minimize the risk of exploitation.

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2024-2860

Affected Products

Brocade Sannav