CVE-2022-43933

MEDIUM

Brocade SANnav <2.2.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

An information exposure through log file vulnerability exists in Brocade SANnav before Brocade SANnav 2.2.2, where configuration secrets are logged in supportsave. Supportsave file is generated by an admin user troubleshooting the switch. The Logged information may include usernames and passwords, and secret keys.

Scores

CVSS v3 4.4
EPSS 0.0003
EPSS Percentile 7.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-532 CWE-538
Status published
Products (1)
broadcom/brocade_sannav < 2.2.2
Published Nov 21, 2024
Tracked Since Feb 18, 2026