CVE-2024-5460

A vulnerability in the default configuration of the Simple Network 
Management Protocol (SNMP) feature of Brocade Fabric OS versions before 
v9.0.0 could allow an authenticated, remote attacker to read data from 
an affected device via SNMP. The vulnerability is due to hard-coded, 
default community string in the configuration file for the SNMP daemon. 
An attacker could exploit this vulnerability by using the static 
community string in SNMP version 1 queries to an affected device.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.1 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
brocadeCNA
8.1 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CISA-ADPADP
---
---
CVEADP
---
---