First published: Wed Aug 30 2023(Updated: )
The firmwaredownload command on Brocade Fabric OS v9.2.0 could log the FTP/SFTP/SCP server password in clear text in the SupportSave file when performing a downgrade from Fabric OS v9.2.0 to any earlier version of Fabric OS.
Credit: sirt@brocade.com sirt@brocade.com
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom Fabric Operating System | =9.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-3489.
The severity of CVE-2023-3489 is high (7.5).
The affected software version is Brocade Fabric OS v9.2.0.
An attacker can exploit this vulnerability by performing a downgrade from Fabric OS v9.2.0 to any earlier version of Fabric OS and capturing the FTP/SFTP/SCP server password in clear text.
Yes, please refer to the provided reference link for information on how to fix this vulnerability.