PT-2024-23171 · Brocade · Brocade Sannav Ova
Pierre Barre
·
Published
2024-04-19
·
Updated
2025-02-04
·
CVE-2024-29962
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Brocade SANnav OVA versions prior to 2.3.1
Brocade SANnav OVA version 2.3.0a
Description
The issue is related to an insecure file permission setting that makes files world-readable. This could allow a local user without the required privileges to access sensitive information or a Java binary.
Recommendations
For Brocade SANnav OVA versions prior to 2.3.1, update to version 2.3.1 or later to resolve the issue.
For Brocade SANnav OVA version 2.3.0a, update to version 2.3.1 or later to resolve the issue.
As a temporary workaround, consider restricting access to sensitive files and Java binaries to minimize the risk of exploitation.
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Brocade Sannav Ova