7.5

CVE-2023-3489

firmwaredownload command could log servers passwords in clear text

The 
firmwaredownload command on Brocade Fabric OS v9.2.0 could log the 
FTP/SFTP/SCP server password in clear text in the SupportSave file when 
performing a downgrade from Fabric OS v9.2.0 to any earlier version of 
Fabric OS.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Broadcom ≫ Fabric Operating System Version 9.2.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.3% 0.212
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Brocade 8.6 3.9 4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CWE-312 Cleartext Storage of Sensitive Information

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

https://security.netapp.com/advisory/ntap-20231124-0003/
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/22510
Vendor Advisory