CVE-2024-29956: cleartext password in supportsave logs when a user schedules a switch Supportsave from Brocade SANnav
Published Apr 18, 2024
·Updated
A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints the Brocade SANnav password in clear text in supportsave logs when a user schedules a switch Supportsave from Brocade SANnav.
Affected Software
2 affected components
Brocade SANNav<2.3.1
Broadcom Brocade Sannav<2.3.0a
Event History
Apr 18, 2024
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-29956?
CVE-2024-29956 is classified as a high severity vulnerability due to the exposure of sensitive credentials.
2
How do I fix CVE-2024-29956?
To fix CVE-2024-29956, upgrade to Brocade SANnav version 2.3.1 or later to eliminate clear text password storage.
3
What does CVE-2024-29956 affect?
CVE-2024-29956 affects Brocade SANnav versions prior to 2.3.1 and 2.3.0a.
4
What is the nature of the vulnerability described in CVE-2024-29956?
CVE-2024-29956 is a vulnerability that allows the Brocade SANnav password to be printed in clear text in supportsave logs.
5
Is there a workaround for CVE-2024-29956?
There is no official workaround for CVE-2024-29956; upgrading to the patched version is the only resolution.