CVE-2022-28170
25.10.2022, 21:15
Brocade Fabric OS Web Application services before Brocade Fabric v9.1.0, v9.0.1e, v8.2.3c, v7.4.2j store server and user passwords in the debug statements. This could allow a local user to extract the passwords from a debug file.Enginsight
Vendor | Product | Version |
---|---|---|
broadcom | fabric_operating_system | 𝑥 < 7.4.2j |
broadcom | fabric_operating_system | 8.0.0 ≤ 𝑥 < 8.2.3c |
broadcom | fabric_operating_system | 9.0.0 ≤ 𝑥 < 9.0.1e |
broadcom | fabric_operating_system | 9.1.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References