PT-2024-3488 · Brocade · Brocade Sannav

Pierre Barre

·

Published

2024-04-16

·

Updated

2025-09-02

·

CVE-2024-2859

CVSS v2.0

7.7

High

VectorAV:A/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Brocade SANnav versions (affected versions not specified)
Description The issue is related to inadequate access control in the software, which could allow a remote attacker to impact the confidentiality, integrity, and availability of protected information. By default, SANnav OVA is shipped with the root user login enabled, although it is protected by a password. If an attacker gains access to the root account, they could expose SANnav to remote attacks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Incorrect Default Permissions

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2024-03790
CVE-2024-2859

Affected Products

Brocade Sannav