First published: Tue Jun 25 2024(Updated: )
A vulnerability in the web interface in Brocade Fabric OS before v9.2.1, v9.2.0b, and v9.1.1d prints encoded session passwords on session storage for Virtual Fabric platforms. This could allow an authenticated user to view other users' session encoded passwords.
Credit: sirt@brocade.com
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom Fabric Operating System | >=9.0.0<9.1.1d | |
Broadcom Fabric Operating System | >=9.2.0<9.2.0b | |
Brocade Fabric Operating System | <9.2.1 |
The security update is provided in Brocade Fabric OS v9.2.1, v9.2.0b, v9.1.1d
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-29953 is considered a high severity vulnerability due to its potential to expose encoded session passwords.
To fix CVE-2024-29953, upgrade to Brocade Fabric OS version 9.2.1 or later.
CVE-2024-29953 affects users of Brocade Fabric OS versions earlier than 9.2.1 or those running specific versions of the Broadcom fabric operating system.
CVE-2024-29953 allows authenticated users to view encoded session passwords of other users.
CVE-2024-29953 specifically impacts Virtual Fabric platforms running affected versions of Brocade Fabric OS.