CVE-2023-3489: firmwaredownload command could log servers passwords in clear text
Published Aug 30, 2023
·Updated
The firmwaredownload command on Brocade Fabric OS v9.2.0 could log the FTP/SFTP/SCP server password in clear text in the SupportSave file when performing a downgrade from Fabric OS v9.2.0 to any earlier version of Fabric OS.
Affected Software
1 affected component
Broadcom Fabric Operating System=9.2.0
Event History
Aug 30, 2023
CVE Published
via MITRE·11:56 PM
Data Sourced
via MITRE·11:56 PM
DescriptionSeverityWeakness
Aug 31, 2023
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2023-3489.
2
What is the severity of CVE-2023-3489?
The severity of CVE-2023-3489 is high (7.5).
3
What is the affected software version?
The affected software version is Brocade Fabric OS v9.2.0.
4
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by performing a downgrade from Fabric OS v9.2.0 to any earlier version of Fabric OS and capturing the FTP/SFTP/SCP server password in clear text.
5
Is there a fix available for this vulnerability?
Yes, please refer to the provided reference link for information on how to fix this vulnerability.