CVE-2024-10405

MEDIUM

Broadcom Brocade Sannav < 2.3.1b - Broken Cryptographic Algorithm

Title source: rule
STIX 2.1

Description

Brocade SANnav before SANnav 2.3.1b enables weak TLS ciphers on ports 443 and 18082. In case of a successful exploit, an attacker can read Brocade SANnav data stream that includes monitored Brocade Fabric OS switches performance data, port status, zoning information, WWNs, IP Addresses, but no customer data, no personal data and no secrets or passwords, as it travels across the network.

Scores

CVSS v3 5.3
EPSS 0.0011
EPSS Percentile 29.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-327
Status published
Products (1)
broadcom/brocade_sannav < 2.3.1b
Published Feb 15, 2025
Tracked Since Feb 18, 2026