Missing Encryption of Sensitive Data in Brocade SANnav - CVE-2022-28168
Published: June 24, 2022 / Updated: June 24, 2022
Vulnerability identifier: #VU64653
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-28168
CWE-ID: CWE-311
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to encoded scp-server passwords being stored using Base64 encoding. A local user with access to log files can decode all passwords.
Affected software
Brocade SANnav
HPE SANnav Management Software
Connectrix (Brocade)
HPE SANnav Management Software
Connectrix (Brocade)
How to mitigate CVE-2022-28168
Install updates from vendor's website.
Brocade SANnav - addressed in versions 2.2.0.2, 2.1.1.8
HPE SANnav Management Software - addressed in versions 2.1.1.8, 2.2.0.2
Connectrix (Brocade) - addressed in versions 2.1.1.8, 2.2.0.2
HPE SANnav Management Software - addressed in versions 2.1.1.8, 2.2.0.2
Connectrix (Brocade) - addressed in versions 2.1.1.8, 2.2.0.2