A vulnerability affects Brocade SANnav before v2.3.1 and v2.3.0a. It allows a Brocade SANnav service to send ping commands in the background at regular intervals to gridgain.com to check if updates are available for the Component. This could make an unauthenticated, remote attacker aware of the behavior and launch a supply-chain attack against a Brocade SANnav appliance.
History

Tue, 04 Feb 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Broadcom
Broadcom brocade Sannav
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:broadcom:brocade_sannav:*:*:*:*:*:*:*:*
Vendors & Products Broadcom
Broadcom brocade Sannav

cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published:

Updated: 2024-08-02T01:17:58.481Z

Reserved: 2024-03-22T05:23:33.322Z

Link: CVE-2024-29961

cve-icon Vulnrichment

Updated: 2024-08-02T01:17:58.481Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-19T04:15:10.553

Modified: 2025-02-04T15:52:04.420

Link: CVE-2024-29961

cve-icon Redhat

No data.