Brocade Fabric OS
cpe:2.3:o:broadcom:brocade_fabric_operating_system:*:*:*:*:*:*:*, +4 more
- < 9.2.0
A vulnerability exists in Brocade Fabric OS versions prior to 9.2.0, where SNMP passwords can be exposed in plaintext if password encryption is not enabled. The unencrypted passwords may be revealed in a configupload or supportsave capture. An attacker could use these passwords to retrieve values of supported OIDs through SNMPv3 queries, and there are also a limited number of MIB objects that can be modified.
Exposing SNMP passwords in clear text, allowing unauthorized access to SNMPv3 functionalities and potential modification of certain MIB objects.
To address this vulnerability, SNMP password encryption should be enabled using the 'snmpconfig --set snmpv3 -enable passwd_encryption' command. After enabling encryption, it's recommended to change the SNMP authpassword and privpassword, as these secrets could have been previously exposed. Brocade switches with Fabric OS 9.2.0 and later have SNMP password encryption enabled by default, but those with earlier versions do not. For switches prior to 9.2.0, a factory reset will not enable encryption, so it must be done manually.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.