CVE-2024-10405
MEDIUMBrocade SANnav < 2.3.1b - Use of Weak TLS Ciphers on Ports 443 and 18082
Title source: llmDescription
Brocade SANnav before SANnav 2.3.1b enables weak TLS ciphers on ports 443 and 18082. In case of a successful exploit, an attacker can read Brocade SANnav data stream that includes monitored Brocade Fabric OS switches performance data, port status, zoning information, WWNs, IP Addresses, but no customer data, no personal data and no secrets or passwords, as it travels across the network.
References (1)
Core 1
Core References
Scores
CVSS v3
5.3
EPSS
0.0018
EPSS Percentile
8.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-327
Status
published
Products (1)
broadcom/brocade_sannav
< 2.3.1b
Published
Feb 15, 2025
Tracked Since
Feb 18, 2026