CVE-2023-3489

HIGH

Brocade Fabric OS v9.2.0 - Cleartext Storage of Sensitive Information in SupportSave File

Title source: llm
STIX 2.1

Description

The firmwaredownload command on Brocade Fabric OS v9.2.0 could log the FTP/SFTP/SCP server password in clear text in the SupportSave file when performing a downgrade from Fabric OS v9.2.0 to any earlier version of Fabric OS.

Scores

CVSS v3 8.6
EPSS 0.0008
EPSS Percentile 24.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-312
Status published
Products (1)
broadcom/fabric_operating_system 9.2.0
Published Aug 31, 2023
Tracked Since Feb 18, 2026