PT-2024-4303 · Brocade · Brocade Sannav Ova

·

CVE-2024-29966

·

Published

2024-04-17

·

Updated

2025-02-04

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Brocade SANnav OVA versions prior to 2.3.1 Brocade SANnav OVA version 2.3.0a
Description The issue is related to the use of hard-coded credentials in the documentation of the Brocade SANnav appliance, which can be used as the root password. This could allow an unauthenticated attacker to gain full access to the appliance.
Recommendations For Brocade SANnav OVA versions prior to 2.3.1, update to version 2.3.1 or later. For Brocade SANnav OVA version 2.3.0a, update to version 2.3.1 or later. As a temporary workaround, consider changing the root password to a unique and secure value until a patch is applied.

Fix

Information Disclosure

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-04790
CVE-2024-29966

Affected Products

Brocade Sannav Ova