5.7

CVE-2023-31423

Possible information exposure through log file vulnerability

Possible
 information exposure through log file vulnerability where sensitive 
fields are recorded in the configuration log without masking on Brocade 
SANnav before v2.3.0 and 2.2.2a. Notes:
 To access the logs, the local attacker must have access to an already collected Brocade SANnav "supportsave" 
outputs.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
BroadcomBrocade Sannav Version < 2.2.2a
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.04% 0.128
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
sirt@brocade.com 5.7 2.1 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
CWE-312 Cleartext Storage of Sensitive Information

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.