GPU VulnDB

Database/Firmware, BMC & network fabric

Brocade Fabric OS (firmware download credential capture): Fabric OS captures the SFTP/FTP server password used

CVE-2024-10403Firmware, BMC & network fabriccurated

Impact

Fabric OS captures the SFTP/FTP server password used for a firmware download. The credential to your firmware distribution server ends up recoverable from the switch — and that server holds the images you install on every switch in the fabric, so it is a step from 'read a password' to 'supply the next firmware image'. Companion CVE-2023-3489 logs the same password in clear text into SupportSave bundles, which then get emailed to vendor support.

Who can reach it

An attacker with access to the switch or to a SupportSave bundle taken from it.

What to do

Upgrade Fabric OS past 8.2.3e2 / 9.2.0c / 9.2.1a as applicable — firmware install plus reboot. Immediately: rotate the firmware-server credential, use a single-purpose account with read-only access to the image share, and scrub existing SupportSave archives before sharing them with support.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.