Lucene search

K
broadcomBroadcom Security ResponseBSNSA23247
HistoryApr 17, 2024 - 12:00 a.m.

Hardcoded TLS keys used by Docker (CVE-2024-29963).

2024-04-1700:00:00
Broadcom Security Response
support.broadcom.com
5
brocade sannav
ova
docker
remote registries
tls
hardcoded keys
mitm
cve-2024-29963

8.6 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.2%

Brocade SANnav OVA before v2.3.1, and v2.3.0a, contain hardcoded TLS keys used by Docker.

** **Brocade SANnav doesn’t have access to remote Docker registries, and knowledge of the keys is a minimal risk as SANnav is prevented from communicating with Docker registries

VEX code: Inline_mitigations_already_exist

Affected configurations

Vulners
Node
broadcombrocade_sannavRange<2.3.0a
CPENameOperatorVersion
brocade sannavlt2.3.0a

8.6 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.2%

Related for BSNSA23247