Database/Firmware, BMC & network fabric
Brocade Fabric OS (firmware download credential capture): Fabric OS captures the SFTP/FTP server password used
Impact
Fabric OS captures the SFTP/FTP server password used for a firmware download. The credential to your firmware distribution server ends up recoverable from the switch — and that server holds the images you install on every switch in the fabric, so it is a step from 'read a password' to 'supply the next firmware image'. Companion CVE-2023-3489 logs the same password in clear text into SupportSave bundles, which then get emailed to vendor support.
Who can reach it
An attacker with access to the switch or to a SupportSave bundle taken from it.
What to do
Upgrade Fabric OS past 8.2.3e2 / 9.2.0c / 9.2.1a as applicable — firmware install plus reboot. Immediately: rotate the firmware-server credential, use a single-purpose account with read-only access to the image share, and scrub existing SupportSave archives before sharing them with support.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.