CVE-2022-28168: High severity broadcom brocade sannav vulnerability
Published Jun 27, 2022
·Updated
In Brocade SANnav before Brocade SANnav v2.2.0.2 and Brocade SANnav2.1.1.8, encoded scp-server passwords are stored using Base64 encoding, which could allow an attacker able to access log files to easily decode the passwords.
Affected Software
2 affected components
Broadcom Sannav<2.1.1.8
Broadcom Sannav>=2.2.0.0<2.2.0.2
Event History
Jun 27, 2022
CVE Published
via MITRE·05:52 PM
Data Sourced
via MITRE·05:52 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2022-28168.
2
What is the severity of CVE-2022-28168?
The severity of CVE-2022-28168 is high with a CVSS score of 7.5.
3
What is affected by CVE-2022-28168?
Brocade SANnav versions up to and including v2.1.1.8, as well as versions between v2.2.0.0 and v2.2.0.2, are affected by CVE-2022-28168.
4
What is the impact of this vulnerability?
The vulnerability allows an attacker with access to log files to easily decode encoded scp-server passwords stored in Base64 format.
5
How can I fix CVE-2022-28168?
To fix CVE-2022-28168, it is recommended to update Brocade SANnav to version v2.2.0.2 or higher.