A vulnerability in the default configuration of the Simple Network
Management Protocol (SNMP) feature of Brocade Fabric OS versions before
v9.0.0 could allow an authenticated, remote attacker to read data from
an affected device via SNMP. The vulnerability is due to hard-coded,
default community string in the configuration file for the SNMP daemon.
An attacker could exploit this vulnerability by using the static
community string in SNMP version 1 queries to an affected device.
References
Configurations
History
04 Feb 2025, 15:24
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:broadcom:fabric_operating_system:*:*:*:*:*:*:*:* | |
First Time |
Broadcom fabric Operating System
Broadcom |
|
References | () https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24409 - Vendor Advisory |
Information
Published : 2024-06-26 00:15
Updated : 2025-02-04 15:24
NVD link : CVE-2024-5460
Mitre link : CVE-2024-5460
CVE.ORG link : CVE-2024-5460
JSON object : View
Products Affected
broadcom
- fabric_operating_system
CWE
CWE-798
Use of Hard-coded Credentials