BSA-2019-866
21613
28 October 2019
28 October 2019
Closed
Low
7.5
N/A
CVE-2019-16207
Summary
Security Advisory ID : BSA-2019-866
Component : SANnav
Revision : 1.0
Brocade SANnav versions before v2.0 use a hard-coded password, which could allow local authenticated attackers to access a back-end database and gain privileges.
The vulnerability could be exploited only if the database service is exposed outside and the database password is left to default during installation
References
CWE-798: Use of Hard-coded Credentials:
Product Confirmed Non Vulnerable
No other Brocade Fibre Channel technology products from Broadcom are currently known to be affected by these vulnerabilities.
Version | Change | Date |
---|---|---|
1.0 | Initial Publication | October 28, 2019 |