Vulnerabilities > CVE-2024-29965 - Insecure Storage of Sensitive Information vulnerability in Broadcom Brocade Sannav

047910
CVSS 5.9 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
local
low complexity
broadcom
CWE-922

Summary

In Brocade SANnav before v2.3.1, and v2.3.0a, it is possible to back up the appliance from the web interface or the command line interface ("SSH"). The resulting backups are world-readable. A local attacker can recover backup files, restore them to a new malicious appliance, and retrieve the passwords of all the switches.

Common Weakness Enumeration (CWE)