Show filters
38 Total Results
Displaying 1-10 of 38
Sort by:
Attacker Value
Unknown
CVE-2024-5462
Disclosure Date: February 15, 2025 (last updated February 15, 2025)
If Brocade Fabric OS before Fabric OS 9.2.0 configuration settings are not set to encrypt SNMP passwords, then the SNMP privsecret / authsecret fields can be exposed in plaintext. The plaintext passwords can be exposed in a configupload capture or a supportsave capture if encryption of passwords is not enabled. An attacker can use these passwords to fetch values of the supported OIDs via SNMPv3 queries. There are also a limited number of MIB objects that can be modified.
0
Attacker Value
Unknown
CVE-2024-5461
Disclosure Date: February 15, 2025 (last updated February 15, 2025)
Implementation of the Simple Network
Management Protocol (SNMP) operating on the Brocade 6547 (FC5022)
embedded switch blade, makes internal script calls to system.sh from
within the SNMP binary. An authenticated attacker could perform command
or parameter injection on SNMP operations that are only enabled on the
Brocade 6547 (FC5022) embedded switch. This injection could allow the
authenticated attacker to issue commands as Root.
0
Attacker Value
Unknown
CVE-2024-4282
Disclosure Date: February 15, 2025 (last updated February 15, 2025)
Brocade SANnav OVA before SANnav 2.3.1b enables SHA1 deprecated setting for SSH for port 22.
0
Attacker Value
Unknown
CVE-2024-10405
Disclosure Date: February 15, 2025 (last updated February 15, 2025)
Brocade SANnav before SANnav 2.3.1b
enables weak TLS ciphers on ports 443 and 18082. In case of a successful
exploit, an attacker can read Brocade SANnav data stream that includes
monitored Brocade Fabric OS switches performance data, port status,
zoning information, WWNs, IP Addresses, but no customer data, no
personal data and no secrets or passwords, as it travels across the
network.
0
Attacker Value
Unknown
CVE-2024-2240
Disclosure Date: February 14, 2025 (last updated February 14, 2025)
Docker daemon in Brocade SANnav before SANnav 2.3.1b runs without auditing. The vulnerability could allow a remote authenticated attacker to execute various attacks.
0
Attacker Value
Unknown
CVE-2025-1053
Disclosure Date: February 14, 2025 (last updated February 14, 2025)
Under certain error conditions at time of SANnav installation or upgrade, the encryption key can be written into and obtained from a Brocade SANnav supportsave. An attacker with privileged access to the Brocade SANnav database could use the encryption key to obtain passwords used by Brocade SANnav.
0
Attacker Value
Unknown
CVE-2024-10404
Disclosure Date: February 14, 2025 (last updated February 14, 2025)
CalInvocationHandler in Brocade
SANnav before 2.3.1b logs sensitive information in clear text. The
vulnerability could allow an authenticated, local attacker to view
Brocade Fabric OS switch sensitive information in clear text. An
attacker with administrative privileges could retrieve sensitive
information including passwords; SNMP responses that contain AuthSecret
and PrivSecret after collecting a “supportsave” or getting access to an
already collected “supportsave”. NOTE: this issue exists because of an incomplete fix for CVE-2024-29952
0
Attacker Value
Unknown
CVE-2024-7517
Disclosure Date: November 21, 2024 (last updated January 05, 2025)
A command injection vulnerability in Brocade Fabric OS before 9.2.0c, and 9.2.1 through 9.2.1a on IP extension platforms could allow a local authenticated attacker to perform a privileged escalation via crafted use of the portcfg command.
This specific exploitation is only possible on IP Extension platforms: Brocade 7810, Brocade 7840, Brocade 7850 and on Brocade X6 or X7 directors with an SX-6 Extension blade installed. The attacker must be logged into the switch via SSH or serial console to conduct the attack.
0
Attacker Value
Unknown
CVE-2024-2859
Disclosure Date: April 27, 2024 (last updated April 27, 2024)
By default, SANnav OVA is shipped with root user login enabled. While protected by a password, access to root could expose SANnav to a remote attacker should they gain access to the root account.
0
Attacker Value
Unknown
CVE-2023-4162
Disclosure Date: August 31, 2023 (last updated September 18, 2024)
A
segmentation fault can occur in Brocade Fabric OS after Brocade Fabric
OS v9.0 and before Brocade Fabric OS v9.2.0a through the passwdcfg
command. This
could allow an authenticated privileged user local user to crash a
Brocade Fabric OS swith using the cli “passwdcfg --set -expire
-minDiff“.
0