CVE-2024-29953: Encoded session passwords on session storage for Virtual Fabric platforms
A vulnerability in the web interface in Brocade Fabric OS before v9.2.1, v9.2.0b, and v9.1.1d prints encoded session passwords on session storage for Virtual Fabric platforms. This could allow an authenticated user to view other users' session encoded passwords.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29953?
CVE-2024-29953 is considered a high severity vulnerability due to its potential to expose encoded session passwords.
How do I fix CVE-2024-29953?
To fix CVE-2024-29953, upgrade to Brocade Fabric OS version 9.2.1 or later.
Who is affected by CVE-2024-29953?
CVE-2024-29953 affects users of Brocade Fabric OS versions earlier than 9.2.1 or those running specific versions of the Broadcom fabric operating system.
What type of data can be accessed through CVE-2024-29953?
CVE-2024-29953 allows authenticated users to view encoded session passwords of other users.
Is CVE-2024-29953 related to specific hardware?
CVE-2024-29953 specifically impacts Virtual Fabric platforms running affected versions of Brocade Fabric OS.