CVE-2024-10404
Severity CVSS v4.0:
Pending analysis
Type:
CWE-312
Cleartext Storage of Sensitive Information
Publication date:
14/02/2025
Last modified:
26/08/2025
Description
CalInvocationHandler in Brocade <br />
SANnav before 2.3.1b logs sensitive information in clear text. The <br />
vulnerability could allow an authenticated, local attacker to view <br />
Brocade Fabric OS switch sensitive information in clear text. An <br />
attacker with administrative privileges could retrieve sensitive <br />
information including passwords; SNMP responses that contain AuthSecret <br />
and PrivSecret after collecting a “supportsave” or getting access to an <br />
already collected “supportsave”. NOTE: this issue exists because of an incomplete fix for CVE-2024-29952
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:broadcom:brocade_sannav:*:*:*:*:*:*:*:* | 2.3.1b (excluding) |
To consult the complete list of CPE names with products and versions, see this page



