Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-29960


In Brocade SANnav server before v2.3.1 and v2.3.0a, the SSH keys inside the OVA image are identical in the VM every time SANnav is installed. Any Brocade SAnnav VM based on the official OVA images is vulnerable to MITM over SSH. An attacker can decrypt and compromise the SSH traffic to the SANnav.


Published

2024-04-19T04:15:10.270

Last Modified

2025-02-04T15:53:21.440

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.8 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-798
  • Type: Primary
    CWE-798

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application broadcom brocade_sannav < 2.3.0a Yes

References