Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-15387


The host SSH servers of Brocade Fabric OS before Brocade Fabric OS v7.4.2h, v8.2.1c, v8.2.2, v9.0.0, and Brocade SANnav before v2.1.1 utilize keys of less than 2048 bits, which may be vulnerable to man-in-the-middle attacks and/or insecure SSH communications.


Published

2021-06-09T16:15:08.307

Last Modified

2024-11-21T05:05:27.830

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.4 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

4.9

Weaknesses
  • Type: Primary
    CWE-326

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application broadcom brocade_sannav < 2.1.1 Yes
Operating System broadcom fabric_operating_system < 7.4.2 Yes
Operating System broadcom fabric_operating_system < 8.2.1 Yes
Operating System broadcom fabric_operating_system 7.4.2 Yes
Operating System broadcom fabric_operating_system 7.4.2a Yes
Operating System broadcom fabric_operating_system 7.4.2b Yes
Operating System broadcom fabric_operating_system 7.4.2c Yes
Operating System broadcom fabric_operating_system 7.4.2d Yes
Operating System broadcom fabric_operating_system 7.4.2f Yes
Operating System broadcom fabric_operating_system 7.4.2g Yes
Operating System broadcom fabric_operating_system 8.2.1 Yes
Operating System broadcom fabric_operating_system 8.2.1a Yes
Operating System broadcom fabric_operating_system 8.2.1b Yes

References