Brocade SANnav OVA SHA1 Deprecation Vulnerability in SSH Port 22

Vulnerability

A vulnerability exists in Brocade SANnav OVA versions prior to 2.3.1b, where the SSH protocol on port 22 uses deprecated SHA1 cryptographic settings. This vulnerability exposes the application to collision attacks, allowing an attacker to create different input data that produces the same hash value, undermining the integrity of the cryptographic communication.

Impact

The use of SHA1 in SSH is vulnerable to collision attacks, where an attacker can manipulate input data to produce identical hash values, potentially leading to unauthorized access or actions.

Remediation

Users can upgrade to Brocade SANnav versions 2.4.0 or 2.3.1b to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
5.0
exploitability
7.0
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.