漏洞标题
博科Fabric OS以明文形式捕获SNMP密码
漏洞描述信息
在Brocade Fabric OS 9.2.0之前的版本中,如果配置设置未将SNMP密码设置为加密状态,则SNMP的privsecret / authsecret字段可能会以明文形式暴露。如果未启用密码加密,在configupload捕获或supportsave捕获中可能会暴露明文密码。攻击者可以使用这些密码通过SNMPv3查询获取支持的OID的值。此外,还可以修改有限数量的MIB对象。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
漏洞类别
敏感数据的明文存储
漏洞标题
Brocade Fabric OS may capture SNMP Passwords in clear text
漏洞描述信息
If Brocade Fabric OS before Fabric OS 9.2.0 configuration settings are not set to encrypt SNMP passwords, then the SNMP privsecret / authsecret fields can be exposed in plaintext. The plaintext passwords can be exposed in a configupload capture or a supportsave capture if encryption of passwords is not enabled. An attacker can use these passwords to fetch values of the supported OIDs via SNMPv3 queries. There are also a limited number of MIB objects that can be modified.
CVSS信息
N/A
漏洞类别
敏感数据的明文传输