Vulnerability index

Browse CVEs

479 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fabric Operating System HIGH 7.5
CVE-2024-10403

Brocade Fabric OS versions before 8.2.3e2, versions 9.0.0 through 9.2.0c, and 9.2.1 through 9.2.1a can capture the SFTP/FTP server password used fo…

Fix: 9.2.0c1 / 9.2.1a1+
Fix from $1,950 2024-11-21
Brocade Sannav MEDIUM 5.5
CVE-2022-43937

Possible information exposure through log file vulnerability where sensitive fields are recorded in the debug-enabled logs when debugging is turned o…

Fix: 2.2.2a+
Fix from $1,600 2024-11-21
Brocade Sannav HIGH 7.5
CVE-2022-43934

Brocade SANnav before Brocade SANnav 2.2.2 supports key exchange algorithms, which are considered weak on ports 24, 6514, 18023, 19094, and 19095.

Fix: 2.2.2+
Fix from $1,950 2024-11-21
Fabric Operating System HIGH 7.1
CVE-2024-7516

A vulnerability in Brocade Fabric OS versions before 9.2.2 could allow man-in-the-middle attackers to conduct remote Service Session Hijacking that m…

Fix: 9.2.2+
Fix from $1,950 2024-11-12
Symantec Privileged Access Management MEDIUM 6.1
CVE-2024-38493

A reflected cross-site scripting (XSS) vulnerability exists in the PAM UI web interface. A remote attacker able to convince a PAM user to click on a …

Fix: after 4.1.7
Fix from $1,600 2024-07-15
Fabric Operating System HIGH 8.1
CVE-2024-5460

A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Brocade Fabric OS versions before v9.0.0 c…

Fix: 9.0.0+
Fix from $1,950 2024-06-26
Fabric Operating System MEDIUM 5.5
CVE-2024-29954

A vulnerability in a password management API in Brocade Fabric OS versions before v9.2.1, v9.2.0b, v9.1.1d, and v8.2.3e prints sensitive information …

Fix: 8.2.3e / 9.1.1d+
Fix from $1,600 2024-06-26
Brocade Sannav HIGH 7.8
CVE-2024-2860

The PostgreSQL implementation in Brocade SANnav versions before 2.3.0a is vulnerable to an incorrect local authentication flaw. An attacker accessing…

Fix: 2.3.0a+
Fix from $1,950 2024-05-08
Brocade Sannav HIGH 7.2
CVE-2024-2859

By default, SANnav OVA is shipped with root user login enabled. While protected by a password, access to root could expose SANnav to a remote attack…

Fix: 2.3.0+
Fix from $1,950 2024-04-27
Brocade Sannav CRITICAL 9.8
CVE-2024-4173

A vulnerability in Brocade SANnav exposes Kafka in the wan interface. The vulnerability could allow an unauthenticated attacker to perform various a…

Fix: 2.2.0+
Fix from $2,300 2024-04-25
Brocade Sannav HIGH 7.5
CVE-2024-4161

In Brocade SANnav, before Brocade SANnav v2.3.0, syslog traffic received clear text. This could allow an unauthenticated, remote attacker to captur…

Fix: 2.3.0+
Fix from $1,950 2024-04-25
Brocade Sannav MEDIUM 5.3
CVE-2024-4159

Brocade SANnav before v2.3.0a lacks protection mechanisms on port 2377/TCP and 7946/TCP, which could allow an unauthenticated attacker to sniff the S…

Fix: 2.3.0a+
Fix from $1,600 2024-04-25
Brocade Sannav HIGH 7.5
CVE-2024-29969

When a Brocade SANnav installation is upgraded from Brocade SANnav v2.2.2 to Brocade SANnav 2.3.0, TLS/SSL weak message authentication code ciphers a…

Fix: 2.3.0a+
Fix from $1,950 2024-04-19
Brocade Sannav MEDIUM 6.5
CVE-2024-29968

An information disclosure vulnerability exists in Brocade SANnav before v2.3.1 and v2.3.0a when Brocade SANnav instances are configured in disaster r…

Fix: 2.3.0a+
Fix from $1,600 2024-04-19
Brocade Sannav CRITICAL 9.8
CVE-2024-29966

Brocade SANnav OVA before v2.3.1 and v2.3.0a contain hard-coded credentials in the documentation that appear as the appliance's root password. The vu…

Fix: 2.3.0a+
Fix from $2,300 2024-04-19
Brocade Sannav MEDIUM 6.5
CVE-2024-29964

Brocade SANnav versions before v2.3.0a do not correctly set permissions on files, including docker files. An unprivileged attacker who gains access t…

Fix: 2.3.0a+
Fix from $1,600 2024-04-19
Brocade Sannav MEDIUM 6.0
CVE-2024-29967

In Brocade SANnav before Brocade SANnav v2.31 and v2.3.0a, it was observed that Docker instances inside the appliance have insecure mount points, all…

Fix: 2.3.0a+
Fix from $1,600 2024-04-19
Brocade Sannav MEDIUM 5.9
CVE-2024-29965

In Brocade SANnav before v2.3.1, and v2.3.0a, it is possible to back up the appliance from the web interface or the command line interface ("SSH"). T…

Fix: 2.3.0a+
Fix from $1,600 2024-04-19
Brocade Sannav MEDIUM 5.5
CVE-2024-29962

Brocade SANnav OVA before v2.3.1 and v2.3.0a have an insecure file permission setting that makes files world-readable. This could allow a local user …

Fix: 2.3.0a+
Fix from $1,600 2024-04-19
Brocade Sannav HIGH 8.6
CVE-2024-29959

A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints Brocade Fabric OS switch encrypted passwords in the Brocade SANnav Standby node's …

Fix: 2.3.0a+
Fix from $1,950 2024-04-19
Brocade Sannav HIGH 8.2
CVE-2024-29961

A vulnerability affects Brocade SANnav before v2.3.1 and v2.3.0a. It allows a Brocade SANnav service to send ping commands in the background at regul…

Fix: 2.3.0a+
Fix from $1,950 2024-04-19
Brocade Sannav HIGH 7.5
CVE-2024-29960

In Brocade SANnav server before v2.3.1 and v2.3.0a, the SSH keys inside the OVA image are identical in the VM every time SANnav is installed. Any Bro…

Fix: 2.3.0a+
Fix from $1,950 2024-04-19
Brocade Sannav HIGH 7.5
CVE-2024-29957

When Brocade SANnav before v2.3.1 and v2.3.0a servers are configured in Disaster Recovery mode, the encryption key is stored in the DR log files. Thi…

Fix: 2.3.0a+
Fix from $1,950 2024-04-19
Brocade Sannav MEDIUM 6.5
CVE-2024-29958

A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints the encryption key in the console when a privileged user executes the script to re…

Fix: 2.3.0a+
Fix from $1,600 2024-04-19
Brocade Sannav MEDIUM 6.5
CVE-2024-29956

A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints the Brocade SANnav password in clear text in supportsave logs when a user schedule…

Fix: 2.3.0a+
Fix from $1,600 2024-04-18
Brocade Sannav MEDIUM 5.5
CVE-2024-29952

A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow an authenticated user to print the Auth, Priv, and SSL key store passwords in…

Fix: 2.3.0a+
Fix from $1,600 2024-04-17
Brocade Sannav MEDIUM 5.5
CVE-2024-29955

A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow a privileged user to print the SANnav encrypted key in PostgreSQL startup log…

Fix: 2.3.0a+
Fix from $1,600 2024-04-17
Brocade Sannav MEDIUM 5.7
CVE-2024-29951

Brocade SANnav before v2.3.1 and v2.3.0a uses the SHA-1 hash in internal SSH ports that are not open to remote connection.

Fix: 2.3.0a+
Fix from $1,600 2024-04-17
Brocade Sannav MEDIUM 5.9
CVE-2024-29950

The class FileTransfer implemented in Brocade SANnav before v2.3.1, v2.3.0a, uses the ssh-rsa signature scheme, which has a SHA-1 hash. The vulnerabi…

Fix: 2.3.0a+
Fix from $1,600 2024-04-17
Fabric Operating System CRITICAL 9.8
CVE-2023-3454

Remote code execution (RCE) vulnerability in Brocade Fabric OS after v9.0 and before v9.2.0 could allow an attacker to execute arbitrary code and use…

Fix: 9.1.1d1+
Fix from $2,300 2024-04-04