CVE-2023-3489
Severity CVSS v4.0:
Pending analysis
Type:
CWE-312
Cleartext Storage of Sensitive Information
Publication date:
31/08/2023
Last modified:
13/02/2025
Description
The <br />
firmwaredownload command on Brocade Fabric OS v9.2.0 could log the <br />
FTP/SFTP/SCP server password in clear text in the SupportSave file when <br />
performing a downgrade from Fabric OS v9.2.0 to any earlier version of <br />
Fabric OS.
Impact
Base Score 3.x
8.60
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:broadcom:fabric_operating_system:9.2.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://security.netapp.com/advisory/ntap-20231124-0003/
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/22510
- https://security.netapp.com/advisory/ntap-20231124-0003/
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/22510



