First published: Mon Jun 27 2022(Updated: )
Brocade SANnav before Brocade SANvav v. 2.2.0.2 and Brocade SANanv v.2.1.1.8 logs the Brocade Fabric OS switch password in plain text in asyncjobscheduler-manager.log
Credit: sirt@brocade.com sirt@brocade.com
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom Sannav | <2.1.1.8 | |
Broadcom Sannav | >=2.2.0.0<2.2.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-28167.
The severity of CVE-2022-28167 is medium with a CVSS score of 6.5.
Brocade SANnav versions up to 2.1.1.8 and Brocade SANnav versions 2.2.0.0 to 2.2.0.2 are affected by CVE-2022-28167.
CVE-2022-28167 exposes the Brocade Fabric OS switch password in plain text in the asyncjobscheduler-manager.log file.
To fix CVE-2022-28167, update Brocade SANnav to a version higher than 2.2.0.2 or apply the necessary patches provided by Broadcom.