CVE-2024-2860

The PostgreSQL implementation in Brocade SANnav versions before 2.3.0a is vulnerable to an incorrect local authentication flaw. An attacker accessing the VM where the Brocade SANnav is installed can gain access to sensitive data inside the PostgreSQL database.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:broadcom:brocade_sannav:*:*:*:*:*:*:*:*
cpe:2.3:a:broadcom:brocade_sannav:2.3.1:*:*:*:*:*:*:*

History

06 Feb 2025, 17:54

Type Values Removed Values Added
CWE CWE-306
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CPE cpe:2.3:a:broadcom:brocade_sannav:2.3.1:*:*:*:*:*:*:*
cpe:2.3:a:broadcom:brocade_sannav:*:*:*:*:*:*:*:*
First Time Broadcom
Broadcom brocade Sannav
References () https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24260 - () https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24260 - Vendor Advisory

08 May 2024, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-08 02:15

Updated : 2025-02-06 17:54


NVD link : CVE-2024-2860

Mitre link : CVE-2024-2860


JSON object : View

Products Affected

broadcom

  • brocade_sannav
CWE
CWE-306

Missing Authentication for Critical Function