Vulnerability Description
In Brocade SANnav server before v2.3.1 and v2.3.0a, the SSH keys inside the OVA image are identical in the VM every time SANnav is installed. Any Brocade SAnnav VM based on the official OVA images is vulnerable to MITM over SSH. An attacker can decrypt and compromise the SSH traffic to the SANnav.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Broadcom | Brocade Sannav | < 2.3.0a |
Related Weaknesses (CWE)
References
- https://support.broadcom.com/external/content/SecurityAdvisories/0/23244Vendor Advisory
- https://support.broadcom.com/external/content/SecurityAdvisories/0/23244Vendor Advisory
FAQ
What is CVE-2024-29960?
CVE-2024-29960 is a vulnerability with a CVSS score of 6.8 (MEDIUM). In Brocade SANnav server before v2.3.1 and v2.3.0a, the SSH keys inside the OVA image are identical in the VM every time SANnav is installed. Any Brocade SAnnav VM based on the official OVA images is...
How severe is CVE-2024-29960?
CVE-2024-29960 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-29960?
Check the references section above for vendor advisories and patch information. Affected products include: Broadcom Brocade Sannav.