Brocade Sannav vulnerabilities

30 known vulnerabilities affecting brocade/brocade_sannav.

Total CVEs
30
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH11MEDIUM16LOW1

Vulnerabilities

Page 2 of 2
CVE-2024-29964MEDIUMCVSS 6.5vbefore v2.3.0a2024-04-19
CVE-2024-29964 [MEDIUM] CWE-732 CVE-2024-29964: Brocade SANnav versions before v2.3.0a do not correctly set permissions on files, including docker f Brocade SANnav versions before v2.3.0a do not correctly set permissions on files, including docker files. An unprivileged attacker who gains access to the server can read sensitive information from these files.
cvelistv5nvd
CVE-2024-29965MEDIUMCVSS 5.9v before v2.3.1, and v2.3.0a2024-04-19
CVE-2024-29965 [MEDIUM] CWE-922 CVE-2024-29965: In Brocade SANnav before v2.3.1, and v2.3.0a, it is possible to back up the appliance from the web In Brocade SANnav before v2.3.1, and v2.3.0a, it is possible to back up the appliance from the web interface or the command line interface ("SSH"). The resulting backups are world-readable. A local attacker can recover backup files, restore them to a new malicious appliance, and retrieve the passwords of all the switches.
cvelistv5nvd
CVE-2024-29963LOWCVSS 3.8vbefore v2.3.1, and v2.3.0a2024-04-19
CVE-2024-29963 [LOW] CWE-798 CVE-2024-29963: Brocade SANnav OVA before v2.3.1, and v2.3.0a, contain hardcoded TLS keys used by Docker. Note: Bro Brocade SANnav OVA before v2.3.1, and v2.3.0a, contain hardcoded TLS keys used by Docker. Note: Brocade SANnav doesn't have access to remote Docker registries.
cvelistv5nvd
CVE-2024-29956MEDIUMCVSS 6.5vbefore v2.3.1 and v2.3.0a2024-04-18
CVE-2024-29956 [MEDIUM] CWE-312 CVE-2024-29956: A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints the Brocade SANnav password in cl A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints the Brocade SANnav password in clear text in supportsave logs when a user schedules a switch Supportsave from Brocade SANnav.
cvelistv5nvd
CVE-2024-29955MEDIUMCVSS 5.5vbefore v2.3.1 and v2.3.0a2024-04-17
CVE-2024-29955 [MEDIUM] CWE-532 CVE-2024-29955: A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow a privileged user to print t A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow a privileged user to print the SANnav encrypted key in PostgreSQL startup logs. This could provide attackers with an additional, less-protected path to acquiring the encryption key.
cvelistv5nvd
CVE-2024-29952MEDIUMCVSS 5.5vbefore v2.3.1 and v2.3.0a2024-04-17
CVE-2024-29952 [MEDIUM] CWE-312 CVE-2024-29952: A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow an authenticated user to pri A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow an authenticated user to print the Auth, Priv, and SSL key store passwords in unencrypted logs by manipulating command variables.
cvelistv5nvd
CVE-2024-29951MEDIUMCVSS 5.7vbefore v2.3.1 and v2.3.0a2024-04-17
CVE-2024-29951 [MEDIUM] CWE-326 CVE-2024-29951: Brocade SANnav before v2.3.1 and v2.3.0a uses the SHA-1 hash in internal SSH ports that are not open Brocade SANnav before v2.3.1 and v2.3.0a uses the SHA-1 hash in internal SSH ports that are not open to remote connection.
cvelistv5nvd
CVE-2024-29950MEDIUMCVSS 5.9vversions before Brocade SANnav v2.3.1, v2.3.0a2024-04-17
CVE-2024-29950 [MEDIUM] CWE-326 CVE-2024-29950: The class FileTransfer implemented in Brocade SANnav before v2.3.1, v2.3.0a, uses the ssh-rsa signat The class FileTransfer implemented in Brocade SANnav before v2.3.1, v2.3.0a, uses the ssh-rsa signature scheme, which has a SHA-1 hash. The vulnerability could allow a remote, unauthenticated attacker to perform a man-in-the-middle attack.
cvelistv5nvd
CVE-2023-31925MEDIUMCVSS 6.5vBrocade SANnav before v2.3.0 and v2.2.2a 2023-08-31
CVE-2023-31925 [MEDIUM] CWE-312 CVE-2023-31925: Brocade SANnav before v2.3.0 and v2.2.2a stores SNMPv3 Authentication passwords in plaintext. A pr Brocade SANnav before v2.3.0 and v2.2.2a stores SNMPv3 Authentication passwords in plaintext. A privileged user could retrieve these credentials with knowledge and access to these log files. SNMP credentials could be seen in SANnav SupportSave if the capture is performed after an SNMP configuration failure causes an SNMP communication log dump.
cvelistv5nvd
CVE-2022-33187MEDIUMCVSS 4.9vBrocade SANnav versions before v2.2.12022-12-09
CVE-2022-33187 [MEDIUM] CWE-532 CVE-2022-33187: Brocade SANnav before v2.2.1 logs usernames and encoded passwords in debug-enabled logs. The vulner Brocade SANnav before v2.2.1 logs usernames and encoded passwords in debug-enabled logs. The vulnerability could allow an attacker with admin privilege to read sensitive information.
cvelistv5nvd