CVE-2024-29960: Identical SSH keys utilized inside the OVA image (CVE-2024-29960)
In Brocade SANnav server before v2.3.1 and v2.3.0a, the SSH keys inside the OVA image are identical in the VM every time SANnav is installed. Any Brocade SAnnav VM based on the official OVA images is vulnerable to MITM over SSH. An attacker can decrypt and compromise the SSH traffic to the SANnav.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29960?
CVE-2024-29960 is considered a high severity vulnerability due to the potential for MITM attacks over SSH.
How do I fix CVE-2024-29960?
To fix CVE-2024-29960, you should update your Brocade SANnav installations to versions newer than v2.3.1 or v2.3.0a where SSH keys are unique.
What are the implications of CVE-2024-29960?
The implications of CVE-2024-29960 include the possibility of an attacker decrypting SSH traffic, leading to data compromise.
Which versions of Brocade SANnav are affected by CVE-2024-29960?
Brocade SANnav versions before v2.3.1 and v2.3.0a are affected by CVE-2024-29960.
What type of attack is CVE-2024-29960 associated with?
CVE-2024-29960 is associated with Man-in-the-Middle (MITM) attacks over SSH.