2024-04-02 14:13:38 +00:00
{
2024-06-26 00:00:36 +00:00
"data_version" : "4.0" ,
2024-04-02 14:13:38 +00:00
"data_type" : "CVE" ,
"data_format" : "MITRE" ,
"CVE_data_meta" : {
"ID" : "CVE-2024-29953" ,
2024-06-26 00:00:36 +00:00
"ASSIGNER" : "sirt@brocade.com" ,
"STATE" : "PUBLIC"
2024-04-02 14:13:38 +00:00
} ,
"description" : {
"description_data" : [
{
"lang" : "eng" ,
2024-06-26 00:00:36 +00:00
"value" : "A vulnerability in the web interface in Brocade Fabric OS before v9.2.1, v9.2.0b, and v9.1.1d prints encoded session passwords on session storage for Virtual Fabric platforms. \nThis could allow an authenticated user to view other users' session encoded passwords."
}
]
} ,
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng" ,
"value" : "CWE-922 Insecure Storage of Sensitive Information" ,
"cweId" : "CWE-922"
}
]
}
]
} ,
"affects" : {
"vendor" : {
"vendor_data" : [
{
"vendor_name" : "Brocade" ,
"product" : {
"product_data" : [
{
"product_name" : "Fabric OS" ,
"version" : {
"version_data" : [
{
"version_value" : "not down converted" ,
"x_cve_json_5_version_data" : {
"versions" : [
{
"status" : "affected" ,
"version" : "before v9.2.1, v9.2.0b, and v9.1.1d"
}
] ,
"defaultStatus" : "affected"
}
}
]
}
}
]
}
}
]
}
} ,
"references" : {
"reference_data" : [
{
"url" : "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/23227" ,
"refsource" : "MISC" ,
"name" : "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/23227"
}
]
} ,
"generator" : {
"engine" : "Vulnogram 0.2.0"
} ,
"source" : {
"discovery" : "INTERNAL"
} ,
"solution" : [
{
"lang" : "en" ,
"supportingMedia" : [
{
"base64" : false ,
"type" : "text/html" ,
"value" : "\n\n<p>The security update is provided in Brocade Fabric OS v9.2.1, v9.2.0b, v9.1.1d</p>"
}
] ,
"value" : "The security update is provided in Brocade Fabric OS v9.2.1, v9.2.0b, v9.1.1d"
}
] ,
"impact" : {
"cvss" : [
{
"attackComplexity" : "LOW" ,
"attackVector" : "NETWORK" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 4.3 ,
"baseSeverity" : "MEDIUM" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "NONE" ,
"privilegesRequired" : "LOW" ,
"scope" : "UNCHANGED" ,
"userInteraction" : "NONE" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" ,
"version" : "3.1"
2024-04-02 14:13:38 +00:00
}
]
}
}