CVE-2024-29952: Clear text storage of sensistive information by manipulating command variables
Published Apr 17, 2024
·Updated
A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow an authenticated user to print the Auth, Priv, and SSL key store passwords in unencrypted logs by manipulating command variables.
Affected Software
3 affected components
Broadcom Brocade Sannav<2.3.0a
Brocade SANNav<2.3.1
Brocade SANNav
Event History
Apr 17, 2024
CVE Published
via MITRE·09:43 PM
Data Sourced
via MITRE·09:43 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-29952?
CVE-2024-29952 is considered a medium severity vulnerability due to the risk of exposing sensitive passwords in unencrypted logs.
2
How do I fix CVE-2024-29952?
To fix CVE-2024-29952, update Brocade SANnav to version 2.3.1 or later.
3
Who is affected by CVE-2024-29952?
CVE-2024-29952 affects all versions of Brocade SANnav before 2.3.1 and 2.3.0a.
4
What kind of information is exposed due to CVE-2024-29952?
CVE-2024-29952 can expose Auth, Priv, and SSL key store passwords in unencrypted logs.
5
Can CVE-2024-29952 be exploited remotely?
CVE-2024-29952 requires an authenticated user to exploit the vulnerability, meaning remote exploitation is not possible without valid credentials.