Описание
A vulnerability in the web interface in Brocade Fabric OS before v9.2.1, v9.2.0b, and v9.1.1d prints encoded session passwords on session storage for Virtual Fabric platforms. This could allow an authenticated user to view other users' session encoded passwords.
Ссылки
- Vendor Advisory
- Third Party Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 9.0.0 (включая) до 9.1.1d (исключая)Версия от 9.2.0 (включая) до 9.2.0b (исключая)
Одно из
cpe:2.3:o:broadcom:fabric_operating_system:*:*:*:*:*:*:*:*
cpe:2.3:o:broadcom:fabric_operating_system:*:*:*:*:*:*:*:*
EPSS
Процентиль: 58%
0.00366
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-922
CWE-922
Связанные уязвимости
CVSS3: 4.3
github
больше 1 года назад
A vulnerability in the web interface in Brocade Fabric OS before v9.2.1, v9.2.0b, and v9.1.1d prints encoded session passwords on session storage for Virtual Fabric platforms. This could allow an authenticated user to view other users' session encoded passwords.
EPSS
Процентиль: 58%
0.00366
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-922
CWE-922