CVE Vulnerabilities

CVE-2022-43935

Insertion of Sensitive Information into Log File

Published: Nov 21, 2024 | Modified: Feb 04, 2025
CVSS 3.x
4.4
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An information exposure through log file vulnerability exists in Brocade SANnav before Brocade SANnav 2.2.2, where Brocade Fabric OS Switch passwords and authorization IDs are printed in the embedded MLS DB file.

Weakness

The product writes sensitive information to a log file.

Affected Software

Name Vendor Start Version End Version
Brocade_sannav Broadcom * 2.2.2 (excluding)

Potential Mitigations

References