Vulnerabilities > CVE-2022-28170 - Insecure Storage of Sensitive Information vulnerability in Broadcom Fabric Operating System

047910
CVSS 6.5 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
local
low complexity
broadcom
CWE-922

Summary

Brocade Fabric OS Web Application services before Brocade Fabric v9.1.0, v9.0.1e, v8.2.3c, v7.4.2j store server and user passwords in the debug statements. This could allow a local user to extract the passwords from a debug file.

Vulnerable Configurations

Part Description Count
OS
Broadcom
134

Common Weakness Enumeration (CWE)