CVE-2024-2859: By default, SANnav OVA is shipped with root user login enabled (CVE-2024-2859)
Published Apr 27, 2024
·Updated
By default, SANnav OVA is shipped with root user login enabled. While protected by a password, access to root could expose SANnav to a remote attacker should they gain access to the root account.
Affected Software
2 affected components
NetApp SANnav OVA
Broadcom Brocade Sannav<2.3.0
Event History
Apr 27, 2024
CVE Published
via MITRE·12:06 AM
Data Sourced
via MITRE·12:06 AM
DescriptionSeverity
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeaknessAffected Software
Jan 7, 57642
Event
via NVD·07:32 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-2859?
CVE-2024-2859 is considered a high severity vulnerability due to the risks of remote access through the root user account.
2
How do I fix CVE-2024-2859?
To fix CVE-2024-2859, disable root user login in the SANnav OVA settings and implement strong access controls.
3
Which software is affected by CVE-2024-2859?
CVE-2024-2859 affects the Broadcom SANnav OVA software.
4
What are the potential impacts of CVE-2024-2859?
The potential impacts of CVE-2024-2859 include unauthorized access and control of the SANnav system by remote attackers.
5
Is there a workaround for CVE-2024-2859?
A temporary workaround for CVE-2024-2859 is to restrict access to the root account by changing passwords and monitoring access logs.