PT-2024-4303 · Brocade · Brocade Sannav Ova

Pierre Barre

·

Published

2024-04-17

·

Updated

2025-02-04

·

CVE-2024-29966

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Brocade SANnav OVA versions prior to 2.3.1 Brocade SANnav OVA version 2.3.0a
Description The issue is related to the use of hard-coded credentials in the documentation of the Brocade SANnav appliance, which can be used as the root password. This could allow an unauthenticated attacker to gain full access to the appliance.
Recommendations For Brocade SANnav OVA versions prior to 2.3.1, update to version 2.3.1 or later. For Brocade SANnav OVA version 2.3.0a, update to version 2.3.1 or later. As a temporary workaround, consider changing the root password to a unique and secure value until a patch is applied.

Fix

Information Disclosure

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

BDU:2024-04790
CVE-2024-29966

Affected Products

Brocade Sannav Ova