CVE-2024-5460

A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Brocade Fabric OS versions before v9.0.0 could allow an authenticated, remote attacker to read data from an affected device via SNMP. The vulnerability is due to hard-coded, default community string in the configuration file for the SNMP daemon. An attacker could exploit this vulnerability by using the static community string in SNMP version 1 queries to an affected device.
Configurations

Configuration 1 (hide)

cpe:2.3:o:broadcom:fabric_operating_system:*:*:*:*:*:*:*:*

History

04 Feb 2025, 15:24

Type Values Removed Values Added
CPE cpe:2.3:o:broadcom:fabric_operating_system:*:*:*:*:*:*:*:*
First Time Broadcom
Broadcom fabric Operating System
References () https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24409 - () https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24409 - Vendor Advisory

21 Nov 2024, 09:47

Type Values Removed Values Added
References () https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24409 - () https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24409 -
Summary
  • (es) Una vulnerabilidad en la configuración predeterminada de la función del Protocolo simple de administración de red (SNMP) de las versiones de Brocade Fabric OS anteriores a v9.0.0 podría permitir que un atacante remoto autenticado lea datos de un dispositivo afectado a través de SNMP. La vulnerabilidad se debe a una cadena de comunidad predeterminada codificada en el archivo de configuración del demonio SNMP. Un atacante podría aprovechar esta vulnerabilidad utilizando la cadena de comunidad estática en las consultas SNMP versión 1 a un dispositivo afectado.

26 Jun 2024, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-26 00:15

Updated : 2025-02-04 15:24


NVD link : CVE-2024-5460

Mitre link : CVE-2024-5460

CVE.ORG link : CVE-2024-5460


JSON object : View

Products Affected

broadcom

  • fabric_operating_system
CWE
CWE-798

Use of Hard-coded Credentials