CVE-2024-7516 Vulnerability Details

  /     /     /  

CVE-2024-7516 Metadata Quick Info

CVE Published: 12/11/2024 | CVE Updated: 21/11/2024 | CVE Year: 2024
Source: brocade | Vendor: Brocade | Product: Fabric OS
Status : PUBLISHED

CVE-2024-7516 Description

A vulnerability in Brocade Fabric OS versions before 9.2.2 could allow man-in-the-middle attackers to conduct remote Service Session Hijacking that may arise from the attacker\'s ability to forge an SSH key while the Brocade Fabric OS Switch is performing various remote operations initiated by a switch admin.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-322
CWE Name: CWE-322: Key Exchange without Entity Authentication
Source: Brocade

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID: CAPEC-97
CAPEC Description: CAPEC-97 Cryptanalysis


Source: NVD (National Vulnerability Database).