CVE-2024-29952

MEDIUM

Brocade SANnav <2.3.1-2.3.0a - Info Disclosure

Title source: llm
STIX 2.1

Description

A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow an authenticated user to print the Auth, Priv, and SSL key store passwords in unencrypted logs by manipulating command variables.

Scores

CVSS v3 5.5
EPSS 0.0006
EPSS Percentile 18.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-312
Status published
Products (1)
broadcom/brocade_sannav < 2.3.0a
Published Apr 17, 2024
Tracked Since Feb 18, 2026