First published: Tue Aug 01 2023(Updated: )
The Brocade Fabric OS Commands “configupload” and “configdownload” before Brocade Fabric OS v9.1.1c, v8.2.3d, v9.2.0 print scp, sftp, ftp servers passwords in supportsave. This could allow a remote authenticated attacker to access sensitive information.
Credit: sirt@brocade.com sirt@brocade.com
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom Fabric Operating System | <8.2.3d | |
Broadcom Fabric Operating System | >=9.0.0<9.1.1c |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-31426 is a vulnerability in the Brocade Fabric OS that allows a remote authenticated attacker to access sensitive information by printing SCP, SFTP, FTP server passwords in supportsave.
CVE-2023-31426 has a severity rating of 6.5, which is considered medium.
The Brocade Fabric OS versions up to and exclusive of 8.2.3d, and versions between 9.0.0 and 9.1.1c are affected by CVE-2023-31426.
A remote authenticated attacker can exploit CVE-2023-31426 by using the Brocade Fabric OS commands 'configupload' and 'configdownload' to print SCP, SFTP, FTP server passwords in supportsave.
Yes, you can find references for CVE-2023-31426 at the following links: [Broadcom Support](https://support.broadcom.com/external/content/SecurityAdvisories/0/22407) and [NetApp Security Advisory](https://security.netapp.com/advisory/ntap-20230908-0007/).