CVE Vulnerabilities

CVE-2022-28162

Cleartext Storage of Sensitive Information

Published: May 09, 2022 | Modified: Nov 21, 2024
CVSS 3.x
3.3
LOW
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Brocade SANnav before version SANnav 2.2.0 logs the REST API Authentication token in plain text.

Weakness

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Affected Software

NameVendorStart VersionEnd Version
SannavBroadcom*2.2.0 (excluding)

Potential Mitigations

References