漏洞标题
博科 SANnav 加密密钥记录在调试日志中
漏洞描述信息
在SANnav安装或升级过程中,若出现特定错误情况,加密密钥可能会被写入并从Brocade SANnav支持保存文件中获取。攻击者若拥有对Brocade SANnav数据库的特权访问权限,可以利用该加密密钥获取Brocade SANnav所使用的密码。
CVSS信息
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
漏洞类别
使用硬编码的凭证
漏洞标题
Brocade SANnav encryption key is logged in the debug logs
漏洞描述信息
Under certain error conditions at time of SANnav installation or upgrade, the encryption key can be written into and obtained from a Brocade SANnav supportsave. An attacker with privileged access to the Brocade SANnav database could use the encryption key to obtain passwords used by Brocade SANnav.
CVSS信息
N/A
漏洞类别
N/A