CVE-2024-10403: Broadcom Fabric Operating System
High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.
Brocade Fabric OS versions before 8.2.3e2, versions 9.0.0 through 9.2.0c, and 9.2.1 through 9.2.1a can capture the SFTP/FTP server password used for a firmware download operation initiated by SANnav or through WebEM in a weblinker core dump that is later captured via supportsave.
Affected products
- Broadcom Fabric Operating System: before 9.2.0c1 (fixed in 9.2.0c1); from 9.2.1, before 9.2.1a1 (fixed in 9.2.1a1)
Published 2024-11-21. Last modified 2026-06-17.