CVE-2024-10404

Severity CVSS v4.0:
Pending analysis
Type:
CWE-312 Cleartext Storage of Sensitive Information
Publication date:
14/02/2025
Last modified:
26/08/2025

Description

CalInvocationHandler in Brocade <br /> SANnav before 2.3.1b logs sensitive information in clear text. The <br /> vulnerability could allow an authenticated, local attacker to view <br /> Brocade Fabric OS switch sensitive information in clear text. An <br /> attacker with administrative privileges could retrieve sensitive <br /> information including passwords; SNMP responses that contain AuthSecret <br /> and PrivSecret after collecting a “supportsave” or getting access to an <br /> already collected “supportsave”. NOTE: this issue exists because of an incomplete fix for CVE-2024-29952

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:broadcom:brocade_sannav:*:*:*:*:*:*:*:* 2.3.1b (excluding)