Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Identical SSH keys utilized inside the OVA image (CVE-2024-29960)
Vulnerability Description
In Brocade SANnav server before v2.3.1 and v2.3.0a, the SSH keys inside the OVA image are identical in the VM every time SANnav is installed. Any Brocade SAnnav VM based on the official OVA images is vulnerable to MITM over SSH. An attacker can decrypt and compromise the SSH traffic to the SANnav.
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
使用硬编码的凭证
Vulnerability Title
Broadcom Brocade SANnav 安全漏洞
Vulnerability Description
Broadcom Brocade SANnav是美国博通(Broadcom)公司的一套SAN管理平台。 Brocade SANnav v2.3.1 版本和 v2.3.0a 版本存在安全漏洞,该漏洞源于 OVA 映像内的 SSH 密钥是硬编码的,并且每次安装 SANnav 时在 VM 中都是相同的。
CVSS Information
N/A
Vulnerability Type
N/A