CVE-2024-4161: Syslog traffic sent in clear-text
Published Apr 25, 2024
·Updated
In Brocade SANnav, before Brocade SANnav v2.3.0, syslog traffic received clear text. This could allow an unauthenticated, remote attacker to capture sensitive information.
Affected Software
2 affected components
Broadcom Brocade Sannav<2.3.0
Brocade SANNav<2.3.0
Event History
Apr 25, 2024
CVE Published
via MITRE·02:32 AM
Data Sourced
via MITRE·02:32 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-4161?
CVE-2024-4161 is considered a high severity vulnerability due to its potential for unauthorized data capture.
2
How do I fix CVE-2024-4161?
To fix CVE-2024-4161, upgrade Brocade SANnav to version 2.3.0 or later.
3
What type of data is exposed in CVE-2024-4161?
CVE-2024-4161 exposes sensitive information transmitted via clear text syslog traffic.
4
Who is affected by CVE-2024-4161?
Organizations using Brocade SANnav versions prior to 2.3.0 are affected by CVE-2024-4161.
5
Can CVE-2024-4161 be exploited remotely?
Yes, CVE-2024-4161 can be exploited remotely by an unauthenticated attacker.