4.3
CVE-2024-29953
- EPSS 0.27%
- Published 26.06.2024 00:15:10
- Last modified 04.02.2025 15:19:11
- Source sirt@brocade.com
- Teams watchlist Login
- Open Login
A vulnerability in the web interface in Brocade Fabric OS before v9.2.1, v9.2.0b, and v9.1.1d prints encoded session passwords on session storage for Virtual Fabric platforms. This could allow an authenticated user to view other users' session encoded passwords.
Data is provided by the National Vulnerability Database (NVD)
Broadcom ≫ Fabric Operating System Version >= 9.0.0 < 9.1.1d
Broadcom ≫ Fabric Operating System Version >= 9.2.0 < 9.2.0b
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.27% | 0.502 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
sirt@brocade.com | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-922 Insecure Storage of Sensitive Information
The product stores sensitive information without properly limiting read or write access by unauthorized actors.