CVE-2023-31423: Possible information exposure through log file vulnerability
Possible information exposure through log file vulnerability where sensitive fields are recorded in the configuration log without masking on Brocade SANnav before v2.3.0 and 2.2.2a. Notes: To access the logs, the local attacker must have access to an already collected Brocade SANnav "supportsave" outputs.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-31423?
CVE-2023-31423 is a vulnerability that allows for possible information exposure through log file vulnerability where sensitive fields are recorded in the configuration log without masking on Brocade SANnav before v2.3.0 and 2.2.2a.
What is the severity of CVE-2023-31423?
CVE-2023-31423 has a severity rating of 5.7, which is considered medium.
How does CVE-2023-31423 affect Broadcom Brocade SANnav?
CVE-2023-31423 affects versions of Broadcom Brocade SANnav before v2.3.0 and 2.2.2a.
How can an attacker exploit CVE-2023-31423?
An attacker can exploit CVE-2023-31423 by having access to an already collected Brocade SANnav 'supportsave' log.
What is the recommended mitigation for CVE-2023-31423?
To mitigate CVE-2023-31423, it is recommended to update Brocade SANnav to version 2.3.0 or newer.