CVE-2022-43933: configuration secrets are logged in support-save
An information exposure through log file vulnerability exists in Brocade SANnav before Brocade SANnav 2.2.2, where configuration secrets are logged in supportsave. Supportsave file is generated by an admin user troubleshooting the switch. The Logged information may include usernames and passwords, and secret keys.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-43933?
CVE-2022-43933 is categorized as a moderate severity vulnerability due to the potential exposure of sensitive configuration secrets.
How do I fix CVE-2022-43933?
To fix CVE-2022-43933, upgrade to Brocade SANnav version 2.2.2 or later to eliminate the information exposure vulnerability.
What is the impact of CVE-2022-43933?
The impact of CVE-2022-43933 includes unauthorized access to sensitive information such as usernames stored in log files.
Who is affected by CVE-2022-43933?
CVE-2022-43933 affects users of Brocade SANnav versions prior to 2.2.2.
Is there a workaround for CVE-2022-43933?
There are no specific workarounds for CVE-2022-43933 other than applying the recommended software update.