Use of Hard-coded Cryptographic Key in Brocade SANnav - CVE-2022-28166
Published: June 24, 2022 / Updated: June 24, 2022
Vulnerability identifier: #VU64656
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-28166
CWE-ID: CWE-321
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to usage of hardcoded cryptographic key for TLS/SSL communication via ports 443/TCP and 18082/TCP. A remote attacker can intercept and decrypt traffic between client and server.
Affected software
Brocade SANnav
HPE SANnav Management Software
Connectrix (Brocade)
HPE SANnav Management Software
Connectrix (Brocade)
How to mitigate CVE-2022-28166
Install updates from vendor's website.
Brocade SANnav - addressed in versions 2.1.1.8, 2.2.0.2
HPE SANnav Management Software - addressed in versions 2.1.1.8, 2.2.0.2
Connectrix (Brocade) - addressed in versions 2.1.1.8, 2.2.0.2
HPE SANnav Management Software - addressed in versions 2.1.1.8, 2.2.0.2
Connectrix (Brocade) - addressed in versions 2.1.1.8, 2.2.0.2