If Brocade Fabric OS before Fabric OS 9.2.0 configuration...
Moderate severity
Unreviewed
Published
Feb 15, 2025
to the GitHub Advisory Database
•
Updated Feb 15, 2025
Description
Published by the National Vulnerability Database
Feb 15, 2025
Published to the GitHub Advisory Database
Feb 15, 2025
Last updated
Feb 15, 2025
If Brocade Fabric OS before Fabric OS 9.2.0 configuration settings are not set to encrypt SNMP passwords, then the SNMP privsecret / authsecret fields can be exposed in plaintext. The plaintext passwords can be exposed in a configupload capture or a supportsave capture if encryption of passwords is not enabled. An attacker can use these passwords to fetch values of the supported OIDs via SNMPv3 queries. There are also a limited number of MIB objects that can be modified.
References