CVE-2024-29953

MEDIUM

Brocade Fabric OS <9.2.1-9.1.1d - Info Disclosure

Title source: llm
STIX 2.1

Description

A vulnerability in the web interface in Brocade Fabric OS before v9.2.1, v9.2.0b, and v9.1.1d prints encoded session passwords on session storage for Virtual Fabric platforms. This could allow an authenticated user to view other users' session encoded passwords.

Scores

CVSS v3 4.3
EPSS 0.0037
EPSS Percentile 58.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-922
Status published
Products (1)
broadcom/fabric_operating_system 9.0.0 - 9.1.1d
Published Jun 26, 2024
Tracked Since Feb 18, 2026