Brocade Fabric OS versions before 8.2.3e2, versions 9.0.0 through 9.2.0c, and 9.2.1 through 9.2.1a can capture the SFTP/FTP server password used for a firmware download operation initiated by SANnav or through WebEM in a weblinker core dump that is later captured via supportsave.
The product generates a core dump file in a directory, archive, or other resource that is stored, transferred, or otherwise made accessible to unauthorized actors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fabric_operating_system | Broadcom | * | 9.2.0c1 (excluding) |
Fabric_operating_system | Broadcom | 9.2.1 (including) | 9.2.1a1 (excluding) |