Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jx64-r67p-6v8c

Опубликовано: 14 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 4.9

Описание

Under certain error conditions at time of SANnav installation or upgrade, the encryption key can be written into and obtained from a Brocade SANnav supportsave. An attacker with privileged access to the Brocade SANnav database could use the encryption key to obtain passwords used by Brocade SANnav.

Under certain error conditions at time of SANnav installation or upgrade, the encryption key can be written into and obtained from a Brocade SANnav supportsave. An attacker with privileged access to the Brocade SANnav database could use the encryption key to obtain passwords used by Brocade SANnav.

EPSS

Процентиль: 19%
0.00062
Низкий

8.6 High

CVSS4

4.9 Medium

CVSS3

Дефекты

CWE-1295
CWE-532

Связанные уязвимости

CVSS3: 4.9
nvd
12 месяцев назад

Under certain error conditions at time of SANnav installation or upgrade, the encryption key can be written into and obtained from a Brocade SANnav supportsave. An attacker with privileged access to the Brocade SANnav database could use the encryption key to obtain passwords used by Brocade SANnav.

CVSS3: 7.4
fstec
около 1 года назад

Уязвимость компонента Supportsave программного обеспечение для управления сетью SAN Brocade SANnav, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 19%
0.00062
Низкий

8.6 High

CVSS4

4.9 Medium

CVSS3

Дефекты

CWE-1295
CWE-532