2024-07-14 02:06:08 +00:00

60 lines
1.9 KiB
JSON

{
"id": "CVE-2024-29962",
"sourceIdentifier": "sirt@brocade.com",
"published": "2024-04-19T05:15:48.940",
"lastModified": "2024-04-19T13:10:25.637",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Brocade SANnav OVA before v2.3.1 and v2.3.0a have an insecure file permission setting that makes files world-readable. This could allow a local user without the required privileges to access sensitive information or a Java binary.\n\n"
},
{
"lang": "es",
"value": "Brocade SANnav OVA anteriores a v2.3.1 y v2.3.0a tienen una configuraci\u00f3n de permisos de archivos inseguros que hace que los archivos sean legibles en todo el mundo. Esto podr\u00eda permitir que un usuario local sin los privilegios necesarios acceda a informaci\u00f3n confidencial o a un binario de Java."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "sirt@brocade.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"attackVector": "LOCAL",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 5.5,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 1.8,
"impactScore": 3.6
}
]
},
"weaknesses": [
{
"source": "sirt@brocade.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-276"
}
]
}
],
"references": [
{
"url": "https://support.broadcom.com/external/content/SecurityAdvisories/0/23248",
"source": "sirt@brocade.com"
}
]
}