CVE-2023-31925

Severity CVSS v4.0:
Pending analysis
Type:
CWE-312 Cleartext Storage of Sensitive Information
Publication date:
31/08/2023
Last modified:
05/09/2023

Description

Brocade<br /> SANnav before v2.3.0 and v2.2.2a stores SNMPv3 Authentication passwords<br /> in plaintext. A privileged user could retrieve these credentials with <br /> knowledge and access to these log files. SNMP <br /> credentials could be seen in SANnav SupportSave if the capture is <br /> performed after an SNMP configuration failure causes an SNMP <br /> communication log dump.<br /> <br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:broadcom:brocade_sannav:*:*:*:*:*:*:*:* 2.2.2a (excluding)