First published: Fri Apr 19 2024(Updated: )
Brocade SANnav OVA before v2.3.1, and v2.3.0a, contain hardcoded TLS keys used by Docker. Note: Brocade SANnav doesn't have access to remote Docker registries.
Credit: sirt@brocade.com
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom SANnav OVA | <2.3.0a | |
Broadcom SANnav OVA | <2.3.1 | |
Broadcom SANnav OVA |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-29963 is classified as a high-severity vulnerability due to hardcoded TLS keys in Brocade SANnav.
To mitigate CVE-2024-29963, upgrade Brocade SANnav to version 2.3.1 or later.
Brocade SANnav versions prior to 2.3.1 and 2.3.0a are affected by CVE-2024-29963.
CVE-2024-29963 impacts Docker by exposing hardcoded TLS keys, which could lead to secure communication vulnerabilities.
Brocade SANnav does not have access to remote Docker registries, which limits the vulnerability's exploitability.