CVE-2025-7397: CLI history displays inline passwords
A vulnerability in the ascgshell, of Brocade ASCG before 3.3.0 stores any command executed in the Command Line Interface (CLI) in plain text within the command history. A local authenticated user that can access sensitive information like passwords within the CLI history leading to unauthorized access and potential data breaches.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7397?
CVE-2025-7397 has a medium severity rating due to the risk of exposing sensitive information.
How does CVE-2025-7397 affect Brocade ASCG?
CVE-2025-7397 affects Brocade ASCG versions before 3.3.0 by storing executed commands in plain text in the command history.
How do I fix CVE-2025-7397?
To fix CVE-2025-7397, upgrade to Brocade ASCG version 3.3.0 or later.
Who is impacted by CVE-2025-7397?
Local authenticated users with access to the CLI are primarily impacted by CVE-2025-7397.
What information can be exposed due to CVE-2025-7397?
CVE-2025-7397 can expose sensitive information like passwords through the command history.