CVE-2024-29964

Published Apr 19, 2024

Last updated 20 days ago

Overview

Description
Brocade SANnav versions before v2.3.0a do not correctly set permissions on files, including docker files. An unprivileged attacker who gains access to the server can read sensitive information from these files.
Source
sirt@brocade.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
6.5
Impact score
3.6
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Severity
MEDIUM

Weaknesses

sirt@brocade.com
CWE-732
nvd@nist.gov
CWE-732

Social media

Hype score
Not currently trending

Configurations