CVE-2020-15369

HIGH

Brocade Fabric OS <8.2.2c - Info Disclosure

Title source: llm
STIX 2.1

Description

Supportlink CLI in Brocade Fabric OS Versions v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c does not obfuscate the password field, which could expose users’ credentials of the remote server. An authenticated user could obtain the exposed password credentials to gain access to the remote host.

Scores

CVSS v3 8.8
EPSS 0.0022
EPSS Percentile 44.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-521
Status published
Products (9)
broadcom/fabric_operating_system 8.2.1
broadcom/fabric_operating_system 8.2.1a
broadcom/fabric_operating_system 8.2.1b
broadcom/fabric_operating_system 8.2.1c
broadcom/fabric_operating_system 8.2.1d
broadcom/fabric_operating_system 8.2.2
broadcom/fabric_operating_system 8.2.2a
broadcom/fabric_operating_system 8.2.2a1
broadcom/fabric_operating_system 8.2.2b
Published Sep 25, 2020
Tracked Since Feb 18, 2026