The Brocade Fabric OS Commands “configupload” and “configdownload” before Brocade Fabric OS v9.1.1c, v8.2.3d, v9.2.0 print scp, sftp, ftp servers passwords in supportsave. This could allow a remote authenticated attacker to access sensitive information.
The product writes sensitive information to a log file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fabric_operating_system | Broadcom | * | 8.2.3d (excluding) |
Fabric_operating_system | Broadcom | 9.0.0 (including) | 9.1.1c (excluding) |