CVE-2022-28167: Medium severity broadcom brocade sannav vulnerability
Published Jun 27, 2022
·Updated
Brocade SANnav before Brocade SANvav v. 2.2.0.2 and Brocade SANanv v.2.1.1.8 logs the Brocade Fabric OS switch password in plain text in asyncjobscheduler-manager.log
Affected Software
2 affected components
Broadcom Sannav<2.1.1.8
Broadcom Sannav>=2.2.0.0<2.2.0.2
Event History
Jun 27, 2022
CVE Published
via MITRE·05:51 PM
Data Sourced
via MITRE·05:51 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-28167.
2
What is the severity of CVE-2022-28167?
The severity of CVE-2022-28167 is medium with a CVSS score of 6.5.
3
What is affected by CVE-2022-28167?
Brocade SANnav versions up to 2.1.1.8 and Brocade SANnav versions 2.2.0.0 to 2.2.0.2 are affected by CVE-2022-28167.
4
What is the impact of CVE-2022-28167?
CVE-2022-28167 exposes the Brocade Fabric OS switch password in plain text in the asyncjobscheduler-manager.log file.
5
How can I fix CVE-2022-28167?
To fix CVE-2022-28167, update Brocade SANnav to a version higher than 2.2.0.2 or apply the necessary patches provided by Broadcom.