CVE-2024-29951: Brocade SANnav has weak encryption in internal SSH ports
Published Apr 17, 2024
·Updated
Brocade SANnav before v2.3.1 and v2.3.0a uses the SHA-1 hash in internal SSH ports that are not open to remote connection.
Affected Software
3 affected components
Broadcom Brocade Sannav<2.3.0a
Brocade SANNav<2.3.1
Brocade SANNav=2.3.0a
Event History
Apr 17, 2024
CVE Published
via MITRE·07:21 PM
Data Sourced
via MITRE·07:21 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-29951?
CVE-2024-29951 is classified as a high severity vulnerability due to the use of the SHA-1 hash algorithm in Brocade SANnav.
2
How do I fix CVE-2024-29951?
To mitigate CVE-2024-29951, upgrade Brocade SANnav to version 2.3.1 or later.
3
What versions of Brocade SANnav are affected by CVE-2024-29951?
CVE-2024-29951 affects Brocade SANnav versions prior to 2.3.1 and specifically version 2.3.0a.
4
What is the impact of CVE-2024-29951 on Brocade SANnav users?
The impact of CVE-2024-29951 includes potential security risks associated with outdated hashing algorithms.
5
Is the internal SSH port affected by CVE-2024-29951 exposed externally?
No, the internal SSH ports affected by CVE-2024-29951 are not open to remote connection.