Brocade SANnav
cpe:2.3:a:broadcom:brocade_sannav:*:*:*:*:*:*:*
- < 2.3.1b
A vulnerability exists in Brocade SANnav OVA versions prior to 2.3.1b, where the SSH protocol on port 22 uses deprecated SHA1 cryptographic settings. This vulnerability exposes the application to collision attacks, allowing an attacker to create different input data that produces the same hash value, undermining the integrity of the cryptographic communication.
The use of SHA1 in SSH is vulnerable to collision attacks, where an attacker can manipulate input data to produce identical hash values, potentially leading to unauthorized access or actions.
Users can upgrade to Brocade SANnav versions 2.4.0 or 2.3.1b to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.