CVE Vulnerabilities

CVE-2024-29953

Insecure Storage of Sensitive Information

Published: Jun 26, 2024 | Modified: Feb 04, 2025
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A vulnerability in the web interface in Brocade Fabric OS before v9.2.1, v9.2.0b, and v9.1.1d prints encoded session passwords on session storage for Virtual Fabric platforms. This could allow an authenticated user to view other users session encoded passwords.

Weakness

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

Affected Software

NameVendorStart VersionEnd Version
Fabric_operating_systemBroadcom9.0.0 (including)9.1.1d (excluding)
Fabric_operating_systemBroadcom9.2.0 (including)9.2.0b (excluding)

References