First published: Fri Feb 14 2025(Updated: )
If Brocade Fabric OS before Fabric OS 9.2.0 configuration settings are not set to encrypt SNMP passwords, then the SNMP privsecret / authsecret fields can be exposed in plaintext. The plaintext passwords can be exposed in a configupload capture or a supportsave capture if encryption of passwords is not enabled. An attacker can use these passwords to fetch values of the supported OIDs via SNMPv3 queries. There are also a limited number of MIB objects that can be modified.
Credit: sirt@brocade.com
Affected Software | Affected Version | How to fix |
---|---|---|
Brocade FABRIC OS (FOS) | <9.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-5462 is considered a medium severity vulnerability due to the potential exposure of sensitive SNMP passwords.
To fix CVE-2024-5462, configure your Brocade Fabric OS to encrypt SNMP passwords before version 9.2.0.
The risks associated with CVE-2024-5462 include the potential exposure of SNMP privsecret and authsecret fields in plaintext.
Brocade Fabric OS versions before 9.2.0 are affected by CVE-2024-5462.
CVE-2024-5462 affects the security of SNMP configuration settings, specifically the encryption of privsecret and authsecret fields.