In Brocade SANnav before v2.3.1, and v2.3.0a, it is possible to back up the appliance from the web interface or the command line interface ("SSH"). The resulting backups are world-readable. A local attacker can recover backup files, restore them to a new malicious appliance, and retrieve the passwords of all the switches.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: brocade
Published: 2024-04-19T04:48:46.279Z
Updated: 2024-08-02T01:17:58.599Z
Reserved: 2024-03-22T05:32:26.687Z
Link: CVE-2024-29965
Vulnrichment
Updated: 2024-08-02T01:17:58.599Z
NVD
Status : Awaiting Analysis
Published: 2024-04-19T05:15:49.390
Modified: 2024-04-19T13:10:25.637
Link: CVE-2024-29965
Redhat
No data.