8.2.3e2, versions 9.0.0 through 9.2.0c, and 9.2.1 through 9.2.1a can
capture the SFTP/FTP server password used for a firmware download
operation initiated by SANnav or through WebEM in a weblinker core dump
that is later captured via supportsave.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-33422 | Brocade Fabric OS versions before 8.2.3e2, versions 9.0.0 through 9.2.0c, and 9.2.1 through 9.2.1a can capture the SFTP/FTP server password used for a firmware download operation initiated by SANnav or through WebEM in a weblinker core dump that is later captured via supportsave. |
Tue, 04 Feb 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Broadcom
Broadcom fabric Operating System |
|
| Weaknesses | CWE-552 | |
| CPEs | cpe:2.3:o:broadcom:fabric_operating_system:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Broadcom
Broadcom fabric Operating System |
|
| Metrics |
cvssV3_1
|
Thu, 21 Nov 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 21 Nov 2024 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Brocade Fabric OS versions before 8.2.3e2, versions 9.0.0 through 9.2.0c, and 9.2.1 through 9.2.1a can capture the SFTP/FTP server password used for a firmware download operation initiated by SANnav or through WebEM in a weblinker core dump that is later captured via supportsave. | |
| Title | SFTP/FTP password could be captured in plain text in Supportsave generated from SANnav | |
| Weaknesses | CWE-528 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: brocade
Published:
Updated: 2024-11-21T17:53:51.483Z
Reserved: 2024-10-25T23:28:02.085Z
Link: CVE-2024-10403
Updated: 2024-11-21T17:53:48.696Z
Status : Analyzed
Published: 2024-11-21T11:15:16.533
Modified: 2025-02-04T15:28:04.053
Link: CVE-2024-10403
No data.
OpenCVE Enrichment
No data.
EUVD