CVE-2024-10404 - CVE House
Back to Database
Status published Medium CVE-2024-10404

Clear text password seen in switch-asset-collectors-mw in Brocade SANnav supportsave

Vulnerability Description

CalInvocationHandler in Brocade SANnav before 2.3.1b logs sensitive information in clear text. The vulnerability could allow an authenticated, local attacker to view Brocade Fabric OS switch sensitive information in clear text. An attacker with administrative privileges could retrieve sensitive information including passwords; SNMP responses that contain AuthSecret and PrivSecret after collecting a “supportsave” or getting access to an already collected “supportsave”. NOTE: this issue exists because of an incomplete fix for CVE-2024-29952

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-10404

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Brocade SANnav
Vulnerable Versions:
before 2.3.1b

Timeline

Official Publish: February 14th, 2025
Last Modified: February 14th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N

Weaknesses (CWE)