CVE-2023-31426: scp, sftp, ftp servers passwords in supportsave
The Brocade Fabric OS Commands “configupload” and “configdownload” before Brocade Fabric OS v9.1.1c, v8.2.3d, v9.2.0 print scp, sftp, ftp servers passwords in supportsave. This could allow a remote authenticated attacker to access sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-31426?
CVE-2023-31426 is a vulnerability in the Brocade Fabric OS that allows a remote authenticated attacker to access sensitive information by printing SCP, SFTP, FTP server passwords in supportsave.
What is the severity of CVE-2023-31426?
CVE-2023-31426 has a severity rating of 6.5, which is considered medium.
Which software versions are affected by CVE-2023-31426?
The Brocade Fabric OS versions up to and exclusive of 8.2.3d, and versions between 9.0.0 and 9.1.1c are affected by CVE-2023-31426.
How can a remote authenticated attacker exploit CVE-2023-31426?
A remote authenticated attacker can exploit CVE-2023-31426 by using the Brocade Fabric OS commands 'configupload' and 'configdownload' to print SCP, SFTP, FTP server passwords in supportsave.
Are there any references for CVE-2023-31426?
Yes, you can find references for CVE-2023-31426 at the following links: [Broadcom Support](https://support.broadcom.com/external/content/SecurityAdvisories/0/22407) and [NetApp Security Advisory](https://security.netapp.com/advisory/ntap-20230908-0007/).