CVE-2024-29963: Brocade SANnav contains hardcoded TLS keys used by Docker
Published Apr 19, 2024
·Updated
Brocade SANnav OVA before v2.3.1, and v2.3.0a, contain hardcoded TLS keys used by Docker. Note: Brocade SANnav doesn't have access to remote Docker registries.
Affected Software
3 affected components
Broadcom Brocade Sannav<2.3.0a
Brocade SANNav<2.3.1
Brocade SANNav
Event History
Apr 19, 2024
CVE Published
via MITRE·04:04 AM
Data Sourced
via MITRE·04:04 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-29963?
CVE-2024-29963 is classified as a high-severity vulnerability due to hardcoded TLS keys in Brocade SANnav.
2
How do I fix CVE-2024-29963?
To mitigate CVE-2024-29963, upgrade Brocade SANnav to version 2.3.1 or later.
3
Which versions of Brocade SANnav are affected by CVE-2024-29963?
Brocade SANnav versions prior to 2.3.1 and 2.3.0a are affected by CVE-2024-29963.
4
What impact does CVE-2024-29963 have on Docker usage?
CVE-2024-29963 impacts Docker by exposing hardcoded TLS keys, which could lead to secure communication vulnerabilities.
5
Does Brocade SANnav have access to remote Docker registries related to CVE-2024-29963?
Brocade SANnav does not have access to remote Docker registries, which limits the vulnerability's exploitability.