CVE-2024-29958: Encryption key in the console when a privileged user executes the script to replace the Brocade SANnav Management Portal standby node.
A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints the encryption key in the console when a privileged user executes the script to replace the Brocade SANnav Management Portal standby node. This could provide attackers an additional, less protected path to acquiring the encryption key.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29958?
CVE-2024-29958 is considered to be a high severity vulnerability due to the potential disclosure of sensitive encryption keys.
How does CVE-2024-29958 affect Brocade SANnav?
CVE-2024-29958 affects Brocade SANnav versions prior to 2.3.1 and 2.3.0a, allowing a privileged user to inadvertently print sensitive encryption keys.
How do I fix CVE-2024-29958?
To fix CVE-2024-29958, upgrade Brocade SANnav to at least version 2.3.1 or 2.3.0a.
Who is affected by CVE-2024-29958?
Organizations using Brocade SANnav versions prior to 2.3.1 or 2.3.0a should be aware they are affected by CVE-2024-29958.
What is the exploitation potential of CVE-2024-29958?
CVE-2024-29958 has a high exploitation potential, as it can lead to unauthorized access to sensitive encryption keys if manipulated by a privileged user.