CVE-2024-29955: Insertion of Sensitive Information into Brocade SANnav Log File
A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow a privileged user to print the SANnav encrypted key in PostgreSQL startup logs. This could provide attackers with an additional, less-protected path to acquiring the encryption key.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29955?
CVE-2024-29955 is considered a high-severity vulnerability due to the potential risk of exposing the SANnav encryption key.
How do I fix CVE-2024-29955?
To fix CVE-2024-29955, upgrade Brocade SANnav to version 2.3.1 or later.
What does CVE-2024-29955 affect?
CVE-2024-29955 affects Brocade SANnav versions before 2.3.1 and 2.3.0a.
Can CVE-2024-29955 be exploited remotely?
CVE-2024-29955 requires a privileged user to be present for exploitation, making it less likely to be exploited remotely.
What is the impact of CVE-2024-29955?
The impact of CVE-2024-29955 is that it could allow privileged users to unintentionally reveal sensitive encryption keys in PostgreSQL startup logs.