An information exposure through log file vulnerability exists in Brocade SANnav before Brocade SANnav 2.2.2, where configuration secrets are logged in supportsave. Supportsave file is generated by an admin user troubleshooting the switch. The Logged information may include usernames and passwords, and secret keys.
History

Tue, 04 Feb 2025 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Broadcom
Broadcom brocade Sannav
Weaknesses CWE-532
CPEs cpe:2.3:a:broadcom:brocade_sannav:*:*:*:*:*:*:*:*
Vendors & Products Broadcom
Broadcom brocade Sannav

Thu, 21 Nov 2024 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 21 Nov 2024 02:15:00 +0000

Type Values Removed Values Added
Description An information exposure through log file vulnerability exists in Brocade SANnav before Brocade SANnav 2.2.2, where configuration secrets are logged in supportsave. Supportsave file is generated by an admin user troubleshooting the switch. The Logged information may include usernames and passwords, and secret keys.
Title configuration secrets are logged in support-save
Weaknesses CWE-538
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published:

Updated: 2024-11-21T18:01:26.215Z

Reserved: 2022-10-26T19:34:16.360Z

Link: CVE-2022-43933

cve-icon Vulnrichment

Updated: 2024-11-21T17:55:46.097Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-21T11:15:11.077

Modified: 2025-02-04T18:13:36.443

Link: CVE-2022-43933

cve-icon Redhat

No data.