PT-2024-8868 · Brocade · Brocade Fabric Os

CVE-2024-10403

·

Published

2024-11-12

·

Updated

2024-11-21

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Brocade Fabric OS versions before 8.2.3e2 Brocade Fabric OS versions 9.0.0 through 9.2.0c Brocade Fabric OS versions 9.2.1 through 9.2.1a
Description: The issue is related to the exposure of sensitive information, specifically the SFTP/FTP server password used for firmware download operations. This password can be captured in a weblinker core dump file, which may be accessed by unauthorized users. The vulnerability allows an attacker to disclose protected information.
Recommendations: For Brocade Fabric OS versions before 8.2.3e2, upgrade to version 8.2.3e2 or later. For Brocade Fabric OS versions 9.0.0 through 9.2.0c, upgrade to version 9.2.0c or later, but ideally to a version outside of this range. For Brocade Fabric OS versions 9.2.1 through 9.2.1a, upgrade to a version later than 9.2.1a. As a temporary workaround, consider restricting access to the weblinker core dump files to minimize the risk of exploitation.

Fix

Files Accessible to External Parties

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-10535
CVE-2024-10403

Affected Products

Brocade Fabric Os