CVE-2024-29961
Last modified
CVE-2024-29961 is a high-severity vulnerability rated 8.2/10 on the CVSS scale. A vulnerability affects Brocade SANnav before v2.3.1 and v2.3.0a. It allows a Brocade SANnav service to send ping commands in the background at regular intervals to gridgain.com to check if updates are available for the Component. EPSS estimates a 0.76% chance of exploitation in the next 30 days.
Description
A vulnerability affects Brocade SANnav before v2.3.1 and v2.3.0a. It allows a Brocade SANnav service to send ping commands in the background at regular intervals to gridgain.com to check if updates are available for the Component. This could make an unauthenticated, remote attacker aware of the behavior and launch a supply-chain attack against a Brocade SANnav appliance.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Broadcom | Brocade Sannav | < 2.3.0a |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-29961?
How severe is CVE-2024-29961?
How do I fix CVE-2024-29961?
Are you affected by CVE-2024-29961?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
