CVE-2019-16209
- EPSS 0.22%
- Veröffentlicht 08.11.2019 18:15:12
- Zuletzt bearbeitet 21.11.2024 04:30:16
A vulnerability, in The ReportsTrustManager class of Brocade SANnav versions before v2.0, could allow an attacker to perform a man-in-the-middle attack against Secure Sockets Layer(SSL)connections.
CVE-2019-16208
- EPSS 0.08%
- Veröffentlicht 08.11.2019 18:15:12
- Zuletzt bearbeitet 21.11.2024 04:30:16
Password-based encryption (PBE) algorithm, of Brocade SANnav versions before v2.0, has a weakness in generating cryptographic keys that may allow an attacker to decrypt passwords used with several services (Radius, TACAS, etc.).
CVE-2019-16207
- EPSS 0.04%
- Veröffentlicht 08.11.2019 18:15:12
- Zuletzt bearbeitet 21.11.2024 04:30:16
Brocade SANnav versions before v2.0 use a hard-coded password, which could allow local authenticated attackers to access a back-end database and gain privileges.
CVE-2019-16206
- EPSS 0.02%
- Veröffentlicht 08.11.2019 18:15:12
- Zuletzt bearbeitet 21.11.2024 04:30:16
The authentication mechanism, in Brocade SANnav versions before v2.0, logs plaintext account credentials at the ‘trace’ and the 'debug' logging level; which could allow a local authenticated attacker to access sensitive information.