CVE Vulnerabilities

CVE-2024-7516

Key Exchange without Entity Authentication

Published: Nov 12, 2024 | Modified: Feb 04, 2025
CVSS 3.x
7.1
HIGH
Source:
NVD
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability in Brocade Fabric OS versions before 9.2.2 could allow man-in-the-middle attackers to conduct remote Service Session Hijacking that may arise from the attackers ability to forge an SSH key while the Brocade Fabric OS Switch is performing various remote operations initiated by a switch admin.

Weakness

The product performs a key exchange with an actor without verifying the identity of that actor.

Affected Software

Name Vendor Start Version End Version
Fabric_operating_system Broadcom * 9.2.2 (excluding)

Potential Mitigations

References