Vulnerability Description
In Brocade SANnav before v2.3.1, and v2.3.0a, it is possible to back up the appliance from the web interface or the command line interface ("SSH"). The resulting backups are world-readable. A local attacker can recover backup files, restore them to a new malicious appliance, and retrieve the passwords of all the switches.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Broadcom | Brocade Sannav | < 2.3.0a |
Related Weaknesses (CWE)
References
- https://support.broadcom.com/external/content/SecurityAdvisories/0/23250Vendor Advisory
- https://support.broadcom.com/external/content/SecurityAdvisories/0/23250Vendor Advisory
FAQ
What is CVE-2024-29965?
CVE-2024-29965 is a vulnerability with a CVSS score of 6.8 (MEDIUM). In Brocade SANnav before v2.3.1, and v2.3.0a, it is possible to back up the appliance from the web interface or the command line interface ("SSH"). The resulting backups are world-readable. A local a...
How severe is CVE-2024-29965?
CVE-2024-29965 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-29965?
Check the references section above for vendor advisories and patch information. Affected products include: Broadcom Brocade Sannav.