CVE-2024-29953

A vulnerability in the web interface in Brocade Fabric OS before v9.2.1, v9.2.0b, and v9.1.1d prints encoded session passwords on session storage for Virtual Fabric platforms. This could allow an authenticated user to view other users' session encoded passwords.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:broadcom:fabric_operating_system:*:*:*:*:*:*:*:*
cpe:2.3:o:broadcom:fabric_operating_system:*:*:*:*:*:*:*:*

History

04 Feb 2025, 15:19

Type Values Removed Values Added
References () https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/23227 - () https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/23227 - Vendor Advisory
References () https://security.netapp.com/advisory/ntap-20240822-0009/ - () https://security.netapp.com/advisory/ntap-20240822-0009/ - Third Party Advisory
CPE cpe:2.3:o:broadcom:fabric_operating_system:*:*:*:*:*:*:*:*
First Time Broadcom
Broadcom fabric Operating System

21 Nov 2024, 09:08

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad en la interfaz web en Brocade Fabric OS anterior a v9.2.1, v9.2.0b y v9.1.1d imprime contraseñas de sesión codificadas en el almacenamiento de sesiones para plataformas Virtual Fabric. Esto podría permitir que un usuario autenticado vea las contraseñas codificadas de sesión de otros usuarios.
References
  • () https://security.netapp.com/advisory/ntap-20240822-0009/ -
References () https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/23227 - () https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/23227 -

26 Jun 2024, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-26 00:15

Updated : 2025-02-04 15:19


NVD link : CVE-2024-29953

Mitre link : CVE-2024-29953

CVE.ORG link : CVE-2024-29953


JSON object : View

Products Affected

broadcom

  • fabric_operating_system
CWE
CWE-922

Insecure Storage of Sensitive Information