CVE-2024-29950: Brocade SANnav before v2.3.1, v2.3.0a uses weak encryption
Published Apr 17, 2024
·Updated
The class FileTransfer implemented in Brocade SANnav before v2.3.1, v2.3.0a, uses the ssh-rsa signature scheme, which has a SHA-1 hash. The vulnerability could allow a remote, unauthenticated attacker to perform a man-in-the-middle attack.
Affected Software
2 affected components
Broadcom Brocade Sannav<2.3.0a
Brocade SANNav<2.3.1
Event History
Apr 17, 2024
CVE Published
via MITRE·06:21 PM
Data Sourced
via MITRE·06:21 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-29950?
CVE-2024-29950 has a high severity rating due to the potential for remote, unauthenticated man-in-the-middle attacks.
2
How do I fix CVE-2024-29950?
To fix CVE-2024-29950, upgrade Brocade SANnav to version 2.3.1 or later.
3
Which versions of Brocade SANnav are affected by CVE-2024-29950?
Brocade SANnav versions prior to 2.3.1 and 2.3.0a are affected by CVE-2024-29950.
4
What type of attack can CVE-2024-29950 enable?
CVE-2024-29950 can enable remote, unauthenticated man-in-the-middle attacks.
5
Is authentication needed to exploit CVE-2024-29950?
No, CVE-2024-29950 can be exploited by remote, unauthenticated attackers.