Broadcom Brocade SANnav是美国博通(Broadcom)公司的一套SAN管理平台。 Broadcom Brocade SANnav v2.3.1、v2.3.0a 之前版本存在安全漏洞,该漏洞源于FileTransfer 类使用 ssh-rsa 签名方案,该方案具有 SHA-1 哈希值,允许未经身份验证的远程攻击者执行中间人攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Brocade | Brocade SANnav | versions before Brocade SANnav v2.3.1, v2.3.0a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-29951 | 5.7 MEDIUM | Brocade SANnav has weak encryption in internal SSH ports |
| CVE-2024-29952 | 5.5 MEDIUM | Clear text storage of sensistive information by manipulating command variables |
| CVE-2024-29955 | 5.0 MEDIUM | Insertion of Sensitive Information into Brocade SANnav Log File |
No comments yet