CVE-2024-29957

When Brocade SANnav before v2.3.1 and v2.3.0a servers are configured in Disaster Recovery mode, the encryption key is stored in the DR log files. This could provide attackers with an additional, less-protected path to acquiring the encryption key.
Configurations

Configuration 1 (hide)

cpe:2.3:a:broadcom:brocade_sannav:*:*:*:*:*:*:*:*

History

04 Feb 2025, 15:57

Type Values Removed Values Added
References () https://support.broadcom.com/external/content/SecurityAdvisories/0/23241 - () https://support.broadcom.com/external/content/SecurityAdvisories/0/23241 - Vendor Advisory
First Time Broadcom
Broadcom brocade Sannav
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-532
CPE cpe:2.3:a:broadcom:brocade_sannav:*:*:*:*:*:*:*:*

19 Apr 2024, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-19 04:15

Updated : 2025-02-04 15:57


NVD link : CVE-2024-29957

Mitre link : CVE-2024-29957


JSON object : View

Products Affected

broadcom

  • brocade_sannav
CWE
CWE-532

Insertion of Sensitive Information into Log File