CVE-2024-29965

MEDIUM

Brocade SANnav <2.3.1-2.3.0a - Info Disclosure

Title source: llm
STIX 2.1

Description

In Brocade SANnav before v2.3.1, and v2.3.0a, it is possible to back up the appliance from the web interface or the command line interface ("SSH"). The resulting backups are world-readable. A local attacker can recover backup files, restore them to a new malicious appliance, and retrieve the passwords of all the switches.

Scores

CVSS v3 6.8
EPSS 0.0023
EPSS Percentile 46.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-922
Status published
Products (1)
broadcom/brocade_sannav < 2.3.0a
Published Apr 19, 2024
Tracked Since Feb 18, 2026