CVE-2023-31423

Severity CVSS v4.0:
Pending analysis
Type:
CWE-312 Cleartext Storage of Sensitive Information
Publication date:
31/08/2023
Last modified:
13/02/2025

Description

Possible<br /> information exposure through log file vulnerability where sensitive <br /> fields are recorded in the configuration log without masking on Brocade <br /> SANnav before v2.3.0 and 2.2.2a. Notes:<br /> To access the logs, the local attacker must have access to an already collected Brocade SANnav "supportsave" <br /> outputs.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:broadcom:brocade_sannav:*:*:*:*:*:*:*:* 2.2.2a (excluding)