Lucene search

K
broadcomBroadcom Security ResponseBSNSA23227
HistoryApr 30, 2024 - 12:00 a.m.

Encoded session passwords on session storage for Virtual Fabric platforms.(CVE-2024-29953)

2024-04-3000:00:00
Broadcom Security Response
support.broadcom.com
18
vulnerability
web interface
brocade fabric os
session storage
virtual fabric platforms
authenticated user
passwords.

AI Score

6.6

Confidence

Low

EPSS

0

Percentile

9.1%

A vulnerability in the web interface in Brocade Fabric OS before v9.2.1, v9.2.0b, and v9.1.1d prints encoded session passwords on session storage for Virtual Fabric platforms.
This could allow an authenticated user to view other users’ session encoded passwords.

Affected configurations

Vulners
Node
broadcombrocade_fabric_operating_systemRange<9.2.1
OR
broadcombrocade_fabric_operating_systemRange<9.2.0b
OR
broadcombrocade_fabric_operating_systemRange<9.1.1d
VendorProductVersionCPE
broadcombrocade_fabric_operating_system*cpe:2.3:o:broadcom:brocade_fabric_operating_system:*:*:*:*:*:*:*:*

AI Score

6.6

Confidence

Low

EPSS

0

Percentile

9.1%

Related for BSNSA23227