First published: Fri Apr 19 2024(Updated: )
Brocade SANnav OVA before v2.3.1 and v2.3.0a contain hard-coded credentials in the documentation that appear as the appliance's root password. The vulnerability could allow an unauthenticated attacker full access to the Brocade SANnav appliance.
Credit: sirt@brocade.com
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom Brocade SANnav | <2.3.1 | |
Brocade SANnav | <2.3.0a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-29966 is considered a critical vulnerability due to the presence of hard-coded credentials allowing unauthenticated access to the Brocade SANnav appliance.
To fix CVE-2024-29966, upgrade your Brocade SANnav OVA to version 2.3.1 or later.
The risks associated with CVE-2024-29966 include unauthorized access to sensitive data and potential control of the Brocade SANnav appliance by attackers.
CVE-2024-29966 affects users of Brocade SANnav OVA versions before 2.3.1 and 2.3.0a.
CVE-2024-29966 involves hard-coded credentials that could enable unauthorized users to gain full access without authentication.