CVE-2022-33181: Infoleak
An information disclosure vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5, 7.4.2.j could allow a local authenticated attacker to read sensitive files using switch commands “configshow” and “supportlink”.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this information disclosure vulnerability?
The vulnerability ID for this information disclosure vulnerability is CVE-2022-33181.
What software versions are affected by this vulnerability?
The affected software versions are Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5, and 7.4.2.j.
How severe is CVE-2022-33181?
The severity of this vulnerability is medium, with a CVSS score of 5.5.
How can a local authenticated attacker exploit this vulnerability?
A local authenticated attacker can exploit this vulnerability by using switch commands "configshow" and "supportlink" to read sensitive files.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability on the following references: [NetApp Security Advisory](https://security.netapp.com/advisory/ntap-20230127-0006/) and [Broadcom Security Advisory](https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2022-2083).