CVE-2024-29952 Vulnerability Details

  /     /     /  

CVE-2024-29952 Metadata Quick Info

CVE Published: 17/04/2024 | CVE Updated: 02/08/2024 | CVE Year: 2024
Source: brocade | Vendor: Brocade | Product: Brocade SANnav
Status : PUBLISHED

CVE-2024-29952 Description

A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow an authenticated user to print the Auth, Priv, and SSL key store passwords in unencrypted logs by manipulating command variables.

Metrics

CVSS Version: 3.1 | Base Score: 5.5 MEDIUM
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

l➤ Exploitability Metrics:
    Attack Vector (AV)* LOCAL
    Attack Complexity (AC)* LOW
    Privileges Required (PR)* NONE
    User Interaction (UI)* REQUIRED
    Scope (S)* UNCHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* HIGH
    Integrity Impact (I)* NONE
    Availability Impact (A)* NONE

Weakness Enumeration (CWE)

CWE-ID: CWE-312
CWE Name: CWE-312: Cleartext Storage of Sensitive Information
Source: Brocade

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID: CAPEC-37
CAPEC Description: CAPEC-37: Retrieve Embedded Sensitive Data


Source: NVD (National Vulnerability Database).