- EPSS 0.12%
- Veröffentlicht 15.02.2025 00:15:13
- Zuletzt bearbeitet 23.02.2026 14:53:15
Implementation of the Simple Network Management Protocol (SNMP) operating on the Brocade 6547 (FC5022) embedded switch blade, makes internal script calls to system.sh from within the SNMP binary. An authenticated attacker could perform command or...
CVE-2024-5462
- EPSS 0.06%
- Veröffentlicht 15.02.2025 00:15:13
- Zuletzt bearbeitet 23.02.2026 14:56:40
If Brocade Fabric OS before Fabric OS 9.2.0 configuration settings are not set to encrypt SNMP passwords, then the SNMP privsecret / authsecret fields can be exposed in plaintext. The plaintext passwords can be exposed in a configupload capture or a ...
CVE-2024-7517
- EPSS 0.09%
- Veröffentlicht 21.11.2024 11:15:35
- Zuletzt bearbeitet 20.02.2026 21:22:06
A command injection vulnerability in Brocade Fabric OS before 9.2.0c, and 9.2.1 through 9.2.1a on IP extension platforms could allow a local authenticated attacker to perform a privileged escalation via crafted use of the portcfg command. This speci...
CVE-2024-10403
- EPSS 0.11%
- Veröffentlicht 21.11.2024 11:15:16
- Zuletzt bearbeitet 04.02.2025 15:28:04
Brocade Fabric OS versions before 8.2.3e2, versions 9.0.0 through 9.2.0c, and 9.2.1 through 9.2.1a can capture the SFTP/FTP server password used for a firmware download operation initiated by SANnav or through WebEM in a weblinker core dump that ...
CVE-2024-7516
- EPSS 0.15%
- Veröffentlicht 12.11.2024 19:15:18
- Zuletzt bearbeitet 04.02.2025 15:25:22
A vulnerability in Brocade Fabric OS versions before 9.2.2 could allow man-in-the-middle attackers to conduct remote Service Session Hijacking that may arise from the attacker's ability to forge an SSH key while the Brocade Fabric OS Switch is perfor...
- EPSS 23.85%
- Veröffentlicht 09.07.2024 12:15:20
- Zuletzt bearbeitet 04.11.2025 18:16:31
RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Respon...
CVE-2024-5460
- EPSS 0.79%
- Veröffentlicht 26.06.2024 00:15:11
- Zuletzt bearbeitet 04.02.2025 15:24:36
A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Brocade Fabric OS versions before v9.0.0 could allow an authenticated, remote attacker to read data from an affected device via SNMP. The vuln...
CVE-2024-29954
- EPSS 0.05%
- Veröffentlicht 26.06.2024 00:15:10
- Zuletzt bearbeitet 21.11.2024 09:08:41
A vulnerability in a password management API in Brocade Fabric OS versions before v9.2.1, v9.2.0b, v9.1.1d, and v8.2.3e prints sensitive information in log files. This could allow an authenticated user to view the server passwords for protocols such ...
CVE-2024-29953
- EPSS 0.37%
- Veröffentlicht 26.06.2024 00:15:10
- Zuletzt bearbeitet 04.02.2025 15:19:11
A vulnerability in the web interface in Brocade Fabric OS before v9.2.1, v9.2.0b, and v9.1.1d prints encoded session passwords on session storage for Virtual Fabric platforms. This could allow an authenticated user to view other users' session encod...
CVE-2023-5973
- EPSS 0.21%
- Veröffentlicht 05.04.2024 03:15:07
- Zuletzt bearbeitet 13.02.2025 18:16:02
Brocade Web Interface in Brocade Fabric OS v9.x and before v9.2.0 does not properly represent the portName to the user if the portName contains reserved characters. This could allow an authenticated user to alter the UI of the Brocade Switch and ...