CVE-2023-5973 Vulnerability Details

  /     /     /  

CVE-2023-5973 Metadata Quick Info

CVE Published: 05/04/2024 | CVE Updated: 02/08/2024 | CVE Year: 2023
Source: brocade | Vendor: Brocade | Product: Fabric OS
Status : PUBLISHED

CVE-2023-5973 Description

Brocade Web Interface in Brocade Fabric OS v9.x and before v9.2.0 does not properly represent the portName to the user if the portName contains reserved characters. This could allow an authenticated user to alter the UI of the Brocade Switch and change ports display.

Metrics

CVSS Version: 3.1 | Base Score: 4.3 MEDIUM
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

l➤ Exploitability Metrics:
    Attack Vector (AV)* NETWORK
    Attack Complexity (AC)* LOW
    Privileges Required (PR)* LOW
    User Interaction (UI)* NONE
    Scope (S)* UNCHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* NONE
    Integrity Impact (I)* LOW
    Availability Impact (A)* NONE

Weakness Enumeration (CWE)

CWE-ID: CWE-346
CWE Name: CWE-346 Origin Validation Error
Source: Brocade

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID: CAPEC-469
CAPEC Description: CAPEC-469 HTTP DoS


Source: NVD (National Vulnerability Database).