CVE-2024-29953

Published Jun 26, 2024

Last updated 20 days ago

Overview

Description
A vulnerability in the web interface in Brocade Fabric OS before v9.2.1, v9.2.0b, and v9.1.1d prints encoded session passwords on session storage for Virtual Fabric platforms. This could allow an authenticated user to view other users' session encoded passwords.
Source
sirt@brocade.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
4.3
Impact score
1.4
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Severity
MEDIUM

Weaknesses

sirt@brocade.com
CWE-922
nvd@nist.gov
CWE-922

Social media

Hype score
Not currently trending

Configurations