Vulnerabilities > Broadcom > Brocade Sannav > 2.2.2

DATE CVE VULNERABILITY TITLE RISK
2024-04-17 CVE-2024-29951 Inadequate Encryption Strength vulnerability in Broadcom Brocade Sannav
Brocade SANnav before v2.3.1 and v2.3.0a uses the SHA-1 hash in internal SSH ports that are not open to remote connection.
low complexity
broadcom CWE-326
5.7
2024-04-17 CVE-2024-29950 Inadequate Encryption Strength vulnerability in Broadcom Brocade Sannav
The class FileTransfer implemented in Brocade SANnav before v2.3.1, v2.3.0a, uses the ssh-rsa signature scheme, which has a SHA-1 hash. The vulnerability could allow a remote, unauthenticated attacker to perform a man-in-the-middle attack.
network
high complexity
broadcom CWE-326
5.9
2023-08-31 CVE-2023-31423 Cleartext Storage of Sensitive Information vulnerability in Broadcom Brocade Sannav
Possible information exposure through log file vulnerability where sensitive fields are recorded in the configuration log without masking on Brocade SANnav before v2.3.0 and 2.2.2a.
local
low complexity
broadcom CWE-312
5.5
2023-08-31 CVE-2023-31424 Unspecified vulnerability in Broadcom Brocade Sannav
Brocade SANnav Web interface before Brocade SANnav v2.3.0 and v2.2.2a allows remote unauthenticated users to bypass web authentication and authorization.
network
low complexity
broadcom
critical
9.8