CVE-2024-29964

MEDIUM

Brocade SANnav <2.3.0a - Info Disclosure

Title source: llm
STIX 2.1

Description

Brocade SANnav versions before v2.3.0a do not correctly set permissions on files, including docker files. An unprivileged attacker who gains access to the server can read sensitive information from these files.

References (1)

Core 1

Scores

CVSS v3 5.7
EPSS 0.0022
EPSS Percentile 44.9%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-732
Status published
Products (1)
broadcom/brocade_sannav < 2.3.0a
Published Apr 19, 2024
Tracked Since Feb 18, 2026