Back to Database
Status published
High
CVE-2024-29957
Encryption key is stored in the DR log files
Vulnerability Description
When Brocade SANnav before v2.3.1 and v2.3.0a servers are configured in Disaster Recovery mode, the encryption key is stored in the DR log files. This could provide attackers with an additional, less-protected path to acquiring the encryption key.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-29957
Credits & Attribution
No credits recorded in the NVD database.
More from Brocade
View All →CVE-2025-9711
Privilege escalation in Brocade Fabric OS before 9.2.1c3, and 9.2.2 though 9.2.2b
High
8.5
CVE-2025-58383
Privilege escalation via bind command in Brocade Fabric OS
High
8.4
CVE-2025-58382
Privilege escalation in Brocade Fabric before 9.2.1c2 and 9.2.2 through 9.2.2a
High
8.5
CVE-2025-58381
Directory transversal vulnerability in Brocade Fabric OS before 9.2.1c2 and 9.2.2 through 9.2.2a using various shell commands
Medium
4.6
CVE-2025-58380
Directory transversal vulnerability in Brocade Fabric OS before 9.2.1 using grep command
Medium
4.6
Affected Vendor
Brocade
View all reports →Affected Software
Brocade SANnav
Vulnerable Versions:
before v2.3.1 and v2.3.0a
Timeline
Official Publish:
April 19th, 2024
Last Modified:
August 2nd, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N