CVE-2024-2860

T

he PostgreSQL implementation in Brocade SANnav versions before 2.3.0a is vulnerable to an incorrect local authentication flaw. An attacker accessing the VM where the Brocade SANnav is installed can gain access to sensitive data inside the PostgreSQL database.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:broadcom:brocade_sannav:*:*:*:*:*:*:*:*
cpe:2.3:a:broadcom:brocade_sannav:2.3.1:*:*:*:*:*:*:*

History

06 Feb 2025, 17:54

Type Values Removed Values Added
First Time Broadcom
Broadcom brocade Sannav
CPE cpe:2.3:a:broadcom:brocade_sannav:*:*:*:*:*:*:*:*
cpe:2.3:a:broadcom:brocade_sannav:2.3.1:*:*:*:*:*:*:*
References () https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24260 - () https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24260 - Vendor Advisory

21 Nov 2024, 09:10

Type Values Removed Values Added
References () https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24260 - () https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24260 -

08 May 2024, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-08 02:15

Updated : 2025-02-06 17:54


NVD link : CVE-2024-2860

Mitre link : CVE-2024-2860

CVE.ORG link : CVE-2024-2860


JSON object : View

Products Affected
CWE
CWE-306

Missing Authentication for Critical Function