Vulnerability Description
The firmwaredownload command on Brocade Fabric OS v9.2.0 could log the FTP/SFTP/SCP server password in clear text in the SupportSave file when performing a downgrade from Fabric OS v9.2.0 to any earlier version of Fabric OS.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Broadcom | Fabric Operating System | 9.2.0 |
Related Weaknesses (CWE)
References
- https://security.netapp.com/advisory/ntap-20231124-0003/
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/conVendor Advisory
- https://security.netapp.com/advisory/ntap-20231124-0003/
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/conVendor Advisory
FAQ
What is CVE-2023-3489?
CVE-2023-3489 is a vulnerability with a CVSS score of 8.6 (HIGH). The firmwaredownload command on Brocade Fabric OS v9.2.0 could log the FTP/SFTP/SCP server password in clear text in the SupportSave file when performing a downgrade from Fabric OS v9.2.0 to any ea...
How severe is CVE-2023-3489?
CVE-2023-3489 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-3489?
Check the references section above for vendor advisories and patch information. Affected products include: Broadcom Fabric Operating System.