PT-2024-23166 · Brocade · Brocade Sannav

Published

2024-04-17

·

Updated

2025-02-14

·

CVE-2024-29952

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Brocade SANnav versions prior to 2.3.1 Brocade SANnav version 2.3.0a
Description A vulnerability could allow an authenticated user to print the Auth, Priv, and SSL key store passwords in unencrypted logs by manipulating command variables.
Recommendations For Brocade SANnav versions prior to 2.3.1, update to version 2.3.1 or later. For Brocade SANnav version 2.3.0a, update to version 2.3.1 or later. As a temporary workaround, consider restricting access to the log files to minimize the risk of exploitation.

Fix

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2024-29952

Affected Products

Brocade Sannav