First published: Fri Apr 19 2024(Updated: )
In Brocade SANnav before Brocade SANnav v2.31 and v2.3.0a, it was observed that Docker instances inside the appliance have insecure mount points, allowing reading and writing access to sensitive files. The vulnerability could allow a sudo privileged user on the host OS to read and write access to these files.
Credit: sirt@brocade.com
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom SANnav OVA | <v2.31<v2.3.0a | |
Broadcom SANnav OVA | <2.3.0a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-29967 is classified as a high severity vulnerability due to the potential for privilege escalation through insecure mount points in Docker instances.
To mitigate CVE-2024-29967, update Brocade SANnav to version 2.31 or later.
Exploitation of CVE-2024-29967 could allow an attacker with sudo privileges on the host OS to access sensitive files within the Brocade SANnav appliance.
CVE-2024-29967 affects all versions of Brocade SANnav prior to 2.31 and 2.3.0a.
Organizations using Brocade SANnav versions below 2.31 or 2.3.0a may be impacted by CVE-2024-29967.