CVE-2019-16206

Severity CVSS v4.0:
Pending analysis
Type:
CWE-311 Missing Encryption of Sensitive Data
Publication date:
08/11/2019
Last modified:
01/01/2022

Description

The authentication mechanism, in Brocade SANnav versions before v2.0, logs plaintext account credentials at the ‘trace’ and the 'debug' logging level; which could allow a local authenticated attacker to access sensitive information.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:broadcom:brocade_sannav:*:*:*:*:*:*:*:* 2.0 (excluding)