Vulnerability Description
The PostgreSQL implementation in Brocade SANnav versions before 2.3.0a is vulnerable to an incorrect local authentication flaw. An attacker accessing the VM where the Brocade SANnav is installed can gain access to sensitive data inside the PostgreSQL database.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Broadcom | Brocade Sannav | < 2.3.0a |
Related Weaknesses (CWE)
References
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/conVendor Advisory
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/conVendor Advisory
FAQ
What is CVE-2024-2860?
CVE-2024-2860 is a vulnerability with a CVSS score of 7.8 (HIGH). The PostgreSQL implementation in Brocade SANnav versions before 2.3.0a is vulnerable to an incorrect local authentication flaw. An attacker accessing the VM where the Brocade SANnav is installed can g...
How severe is CVE-2024-2860?
CVE-2024-2860 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-2860?
Check the references section above for vendor advisories and patch information. Affected products include: Broadcom Brocade Sannav.