CVE-2020-15387

Severity CVSS v4.0:
Pending analysis
Type:
CWE-326 Inadequate Encryption Strength
Publication date:
09/06/2021
Last modified:
23/08/2021

Description

The host SSH servers of Brocade Fabric OS before Brocade Fabric OS v7.4.2h, v8.2.1c, v8.2.2, v9.0.0, and Brocade SANnav before v2.1.1 utilize keys of less than 2048 bits, which may be vulnerable to man-in-the-middle attacks and/or insecure SSH communications.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:broadcom:brocade_sannav:*:*:*:*:*:*:*:* 2.1.1 (excluding)
cpe:2.3:o:broadcom:fabric_operating_system:*:*:*:*:*:*:*:* 7.4.2 (excluding)
cpe:2.3:o:broadcom:fabric_operating_system:*:*:*:*:*:*:*:* 8.2.0 (including) 8.2.1 (excluding)
cpe:2.3:o:broadcom:fabric_operating_system:7.4.2:*:*:*:*:*:*:*
cpe:2.3:o:broadcom:fabric_operating_system:7.4.2a:*:*:*:*:*:*:*
cpe:2.3:o:broadcom:fabric_operating_system:7.4.2b:*:*:*:*:*:*:*
cpe:2.3:o:broadcom:fabric_operating_system:7.4.2c:*:*:*:*:*:*:*
cpe:2.3:o:broadcom:fabric_operating_system:7.4.2d:*:*:*:*:*:*:*
cpe:2.3:o:broadcom:fabric_operating_system:7.4.2f:*:*:*:*:*:*:*
cpe:2.3:o:broadcom:fabric_operating_system:7.4.2g:*:*:*:*:*:*:*
cpe:2.3:o:broadcom:fabric_operating_system:8.2.1:*:*:*:*:*:*:*
cpe:2.3:o:broadcom:fabric_operating_system:8.2.1a:*:*:*:*:*:*:*
cpe:2.3:o:broadcom:fabric_operating_system:8.2.1b:*:*:*:*:*:*:*