PT-2025-6497 · Brocade · Brocade Fabric Os+1

Published

2025-02-13

·

Updated

2025-08-26

·

CVE-2024-10405

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Brocade SANnav versions prior to 2.3.1b
Description The issue allows an attacker to read the Brocade SANnav data stream, which includes monitored Brocade Fabric OS switches performance data, port status, zoning information, WWNs, and IP Addresses, as it travels across the network. This is due to the enablement of weak TLS ciphers on ports 443 and 18082. No customer data, personal data, secrets, or passwords are exposed.
Recommendations For Brocade SANnav versions prior to 2.3.1b, update to version 2.3.1b or later to resolve the issue. As a temporary workaround, consider restricting access to ports 443 and 18082 to minimize the risk of exploitation.

Fix

Use of a Broken Cryptographic Algorithm

Weakness Enumeration

Related Identifiers

BDU:2025-02105
CVE-2024-10405

Affected Products

Brocade Fabric Os
Brocade Sannav