CVE-2022-28170: Medium severity broadcom fabric operating system vulnerability
Brocade Fabric OS Web Application services before Brocade Fabric v9.1.0, v9.0.1e, v8.2.3c, v7.4.2j store server and user passwords in the debug statements. This could allow a local user to extract the passwords from a debug file.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability identified as CVE-2022-28170?
The vulnerability identified as CVE-2022-28170 is related to Brocade Fabric OS Web Application services storing server and user passwords in debug statements.
How can a local user exploit the CVE-2022-28170 vulnerability?
A local user can exploit the CVE-2022-28170 vulnerability by extracting passwords from a debug file.
Which versions of Brocade Fabric OS are affected by CVE-2022-28170?
The affected versions of Brocade Fabric OS include v7.4.2j, v8.2.3c, v9.0.1e, and v9.1.0.
What is the severity rating of CVE-2022-28170?
CVE-2022-28170 has a severity rating of 6.5, which is considered medium.
Are there any references or additional resources regarding CVE-2022-28170?
Yes, you can refer to the following links for more information about CVE-2022-28170: [NetApp Security Advisory](https://security.netapp.com/advisory/ntap-20230127-0002/) and [Brocade Security Advisory](https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2022-2076).