CVE-2023-5973
Last modified
CVE-2023-5973 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. Brocade Web Interface in Brocade Fabric OS v9.x and before v9.2.0 does not properly represent the portName to the user if the portName contains reserved characters. This could allow an authenticated user to alter the UI of the Brocade Switch and change ports display.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
Brocade Web Interface in Brocade Fabric OS v9.x and before v9.2.0 does not properly represent the portName to the user if the portName contains reserved characters. This could allow an authenticated user to alter the UI of the Brocade Switch and change ports display.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Broadcom | Fabric Operating System | >= 9.0.0, < 9.2.0 |
References
- https://security.netapp.com/advisory/ntap-20240628-0005/Third Party Advisory
- https://security.netapp.com/advisory/ntap-20240628-0005/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-5973?
How severe is CVE-2023-5973?
How do I fix CVE-2023-5973?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-5967Mattermost fails to properly validate requests to the Calls …4.3
- CVE-2023-5968Mattermost fails to properly sanitize the user object when u…4.9
- CVE-2023-5969Mattermost fails to properly sanitize the request to /api/v4…5.3
- CVE-2023-5970Improper authentication in the SMA100 SSL-VPN virtual office…8.8
- CVE-2023-5971The Save as PDF Plugin by Pdfcrowd WordPress plugin before 3…4.8
- CVE-2023-5972A null pointer dereference flaw was found in the nft_inner.c…7.8
- CVE-2023-5974The WPB Show Core WordPress plugin through 2.2 is vulnerable…9.8
- CVE-2023-5975The ImageMapper plugin for WordPress is vulnerable to Cross-…4.3
- CVE-2023-5976Improper Access Control in GitHub repository microweber/micr…4.3
- CVE-2023-5977Rejected reason: Accidental Request.
- CVE-2023-5978In versions of FreeBSD 13-RELEASE before 13-RELEASE-p5, unde…7.5
- CVE-2023-5979The eCommerce Product Catalog Plugin for WordPress plugin be…6.5
Are you affected by CVE-2023-5973?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
