PT-2024-23167 · Brocade · Brocade Fabric Os

Published

2024-06-25

·

Updated

2024-06-26

·

CVE-2024-29953

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Brocade Fabric OS versions prior to 9.2.1 Brocade Fabric OS versions prior to 9.2.0b Brocade Fabric OS versions prior to 9.1.1d
Description A vulnerability in the web interface of Brocade Fabric OS prints encoded session passwords on session storage for Virtual Fabric platforms. This could allow an authenticated user to view other users' session encoded passwords.
Recommendations For versions prior to 9.2.1, update to version 9.2.1 or later. For versions prior to 9.2.0b, update to version 9.2.0b or later. For versions prior to 9.1.1d, update to version 9.1.1d or later.

Fix

Insecure Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-29953

Affected Products

Brocade Fabric Os