PT-2024-4303 · Brocade · Brocade Sannav Ova
Pierre Barre
·
Published
2024-04-17
·
Updated
2025-02-04
·
CVE-2024-29966
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Brocade SANnav OVA versions prior to 2.3.1
Brocade SANnav OVA version 2.3.0a
Description
The issue is related to the use of hard-coded credentials in the documentation of the Brocade SANnav appliance, which can be used as the root password. This could allow an unauthenticated attacker to gain full access to the appliance.
Recommendations
For Brocade SANnav OVA versions prior to 2.3.1, update to version 2.3.1 or later.
For Brocade SANnav OVA version 2.3.0a, update to version 2.3.1 or later.
As a temporary workaround, consider changing the root password to a unique and secure value until a patch is applied.
Fix
Information Disclosure
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Brocade Sannav Ova