Description
If Brocade Fabric OS before Fabric OS 9.2.0 configuration settings are not set to encrypt SNMP passwords, then the SNMP privsecret / authsecret fields can be exposed in plaintext. The plaintext passwords can be exposed in a configupload capture or a supportsave capture if encryption of passwords is not enabled. An attacker can use these passwords to fetch values of the supported OIDs via SNMPv3 queries. There are also a limited number of MIB objects that can be modified.
INFO
Published Date :
2025-02-14T23:48:54.368Z
Last Modified :
2025-02-18T16:26:54.617Z
Source :
brocade
AFFECTED PRODUCTS
The following products are affected by CVE-2024-5462 vulnerability.
| Vendors | Products |
|---|---|
| Broadcom |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2024-5462.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact