When Brocade SANnav before v2.3.1 and v2.3.0a servers are configured in Disaster Recovery mode, the encryption key is stored in the DR log files. This could provide attackers with an additional, less-protected path to acquiring the encryption key.
References
Link | Resource |
---|---|
https://support.broadcom.com/external/content/SecurityAdvisories/0/23241 | Vendor Advisory |
https://support.broadcom.com/external/content/SecurityAdvisories/0/23241 | Vendor Advisory |
Configurations
History
04 Feb 2025, 15:57
Type | Values Removed | Values Added |
---|---|---|
First Time |
Broadcom brocade Sannav
Broadcom |
|
References | () https://support.broadcom.com/external/content/SecurityAdvisories/0/23241 - Vendor Advisory | |
CPE | cpe:2.3:a:broadcom:brocade_sannav:*:*:*:*:*:*:*:* |
Information
Published : 2024-04-19 04:15
Updated : 2025-02-04 15:57
NVD link : CVE-2024-29957
Mitre link : CVE-2024-29957
CVE.ORG link : CVE-2024-29957
JSON object : View
Products Affected
broadcom
- brocade_sannav
CWE
CWE-532
Insertion of Sensitive Information into Log File