PT-2025-6496 · Brocade · Brocade Sannav

Published

2024-10-26

·

Updated

2025-02-14

·

CVE-2024-10404

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Brocade SANnav versions prior to 2.3.1b
Description The issue allows an authenticated, local attacker to view sensitive information in clear text, including passwords and SNMP responses that contain AuthSecret and PrivSecret. This can occur after collecting a "supportsave" or gaining access to an already collected "supportsave". An attacker with administrative privileges could exploit this.
Recommendations For versions prior to 2.3.1b, update to version 2.3.1b or later to resolve the issue. As a temporary workaround, consider restricting access to the "supportsave" feature to minimize the risk of exploitation.

Fix

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

BDU:2025-02082
CVE-2024-10404

Affected Products

Brocade Sannav