PT-2024-3222 · Brocade · Brocade Sannav
Published
2024-04-15
·
Updated
2025-02-04
·
CVE-2024-29950
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Brocade SANnav versions prior to 2.3.1
Brocade SANnav version 2.3.0a
Description
The issue is related to the class FileTransfer in Brocade SANnav, which uses the ssh-rsa signature scheme with a SHA-1 hash. This could allow a remote, unauthenticated attacker to perform a man-in-the-middle attack.
Recommendations
For Brocade SANnav versions prior to 2.3.1, update to version 2.3.1 or later.
For Brocade SANnav version 2.3.0a, update to version 2.3.1 or later.
As a temporary workaround, consider disabling the use of the ssh-rsa signature scheme with SHA-1 hash until a patch is available.
Fix
Inadequate Encryption Strength
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Brocade Sannav