8.6

CVE-2023-3489

firmwaredownload command could log servers passwords in clear text

The 
firmwaredownload command on Brocade Fabric OS v9.2.0 could log the 
FTP/SFTP/SCP server password in clear text in the SupportSave file when 
performing a downgrade from Fabric OS v9.2.0 to any earlier version of 
Fabric OS.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.08% 0.243
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
sirt@brocade.com 8.6 3.9 4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CWE-312 Cleartext Storage of Sensitive Information

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.