CVE-2020-15369
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/09/2020
Last modified:
23/08/2021
Description
Supportlink CLI in Brocade Fabric OS Versions v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c does not obfuscate the password field, which could expose users’ credentials of the remote server. An authenticated user could obtain the exposed password credentials to gain access to the remote host.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
4.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:broadcom:fabric_operating_system:8.2.1:*:*:*:*:*:*:* | ||
cpe:2.3:o:broadcom:fabric_operating_system:8.2.1a:*:*:*:*:*:*:* | ||
cpe:2.3:o:broadcom:fabric_operating_system:8.2.1b:*:*:*:*:*:*:* | ||
cpe:2.3:o:broadcom:fabric_operating_system:8.2.1c:*:*:*:*:*:*:* | ||
cpe:2.3:o:broadcom:fabric_operating_system:8.2.1d:*:*:*:*:*:*:* | ||
cpe:2.3:o:broadcom:fabric_operating_system:8.2.2:*:*:*:*:*:*:* | ||
cpe:2.3:o:broadcom:fabric_operating_system:8.2.2a:*:*:*:*:*:*:* | ||
cpe:2.3:o:broadcom:fabric_operating_system:8.2.2a1:*:*:*:*:*:*:* | ||
cpe:2.3:o:broadcom:fabric_operating_system:8.2.2b:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page