CVE-2024-10403

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
21/11/2024
Last modified:
04/02/2025

Description

Brocade Fabric OS versions before <br /> 8.2.3e2, versions 9.0.0 through 9.2.0c, and 9.2.1 through 9.2.1a can <br /> capture the SFTP/FTP server password used for a firmware download <br /> operation initiated by SANnav or through WebEM in a weblinker core dump <br /> that is later captured via supportsave.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:broadcom:fabric_operating_system:*:*:*:*:*:*:*:* 9.2.0c1 (excluding)
cpe:2.3:o:broadcom:fabric_operating_system:*:*:*:*:*:*:*:* 9.2.1 (including) 9.2.1a1 (excluding)