Show filters
561 Total Results
Displaying 21-30 of 561
Sort by:
Attacker Value
Unknown

CVE-2022-43934

Disclosure Date: November 21, 2024 (last updated February 05, 2025)
Brocade SANnav before Brocade SANnav 2.2.2 supports key exchange algorithms, which are considered weak on ports 24, 6514, 18023, 19094, and 19095.
Attacker Value
Unknown

CVE-2022-43933

Disclosure Date: November 21, 2024 (last updated February 05, 2025)
An information exposure through log file vulnerability exists in Brocade SANnav before Brocade SANnav 2.2.2, where configuration secrets are logged in supportsave. Supportsave file is generated by an admin user troubleshooting the switch. The Logged information may include usernames and passwords, and secret keys.
Attacker Value
Unknown

CVE-2024-7516

Disclosure Date: November 12, 2024 (last updated February 05, 2025)
A vulnerability in Brocade Fabric OS versions before 9.2.2 could allow man-in-the-middle attackers to conduct remote Service Session Hijacking that may arise from the attacker's ability to forge an SSH key while the Brocade Fabric OS Switch is performing various remote operations initiated by a switch admin.
Attacker Value
Unknown

CVE-2024-38496

Disclosure Date: July 15, 2024 (last updated July 16, 2024)
The vulnerability allows a malicious low-privileged PAM user to access information about other PAM users and their group memberships.
0
Attacker Value
Unknown

CVE-2024-38495

Disclosure Date: July 15, 2024 (last updated July 16, 2024)
A specific authentication strategy allows a malicious attacker to learn ids of all PAM users defined in its database.
0
Attacker Value
Unknown

CVE-2024-38494

Disclosure Date: July 15, 2024 (last updated July 16, 2024)
This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by sending a specially crafted HTTP request.
0
Attacker Value
Unknown

CVE-2024-38493

Disclosure Date: July 15, 2024 (last updated September 11, 2024)
A reflected cross-site scripting (XSS) vulnerability exists in the PAM UI web interface. A remote attacker able to convince a PAM user to click on a specially crafted link to the PAM UI web interface could potentially execute arbitrary client-side code in the context of PAM UI.
Attacker Value
Unknown

CVE-2024-38492

Disclosure Date: July 15, 2024 (last updated July 16, 2024)
This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by uploading a specially crafted PAM upgrade file.
0
Attacker Value
Unknown

CVE-2024-38491

Disclosure Date: July 15, 2024 (last updated July 16, 2024)
The vulnerability allows an unauthenticated attacker to read arbitrary information from the database.
0
Attacker Value
Unknown

CVE-2024-36458

Disclosure Date: July 15, 2024 (last updated July 16, 2024)
The vulnerability allows a malicious low-privileged PAM user to perform server upgrade related actions.
0