CVE-2022-43933
Estado: AnalizadaMedia (4.4)—
An information exposure through log file vulnerability exists in Brocade SANnav before Brocade SANnav 2.2.2, where configuration secrets are logged in supportsave. Supportsave file is generated by an admin user troubleshooting the switch. The Logged information may include usernames and passwords, and secret keys.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 4.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.26%
- Percentil entre todas las CVEs puntuadas: 16
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-538
- CWE-532
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-43933",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2022-43933",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-11-21T17:55:44.908275Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "sirt@brocade.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.4,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 0.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.4,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 0.8
}
]
},
"affected": [
{
"source": "sirt@brocade.com",
"affectedData": [
{
"vendor": "Brocade",
"product": "SANnav",
"versions": [
{
"status": "affected",
"version": "before Brocade SANnav 2.2.2"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2024-11-21T11:15:11.077",
"references": [
{
"url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/21221",
"tags": [
"Vendor Advisory"
],
"source": "sirt@brocade.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "sirt@brocade.com",
"description": [
{
"lang": "en",
"value": "CWE-538"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-532"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An information exposure through log file vulnerability exists in Brocade SANnav before Brocade SANnav 2.2.2, where configuration secrets are logged in supportsave. Supportsave file is generated by an admin user troubleshooting the switch. The Logged information may include usernames and passwords, and secret keys."
},
{
"lang": "es",
"value": "Existe una vulnerabilidad de exposición de información a través de un archivo de registro en Brocade SANnav anterior a Brocade SANnav 2.2.2, donde los secretos de configuración se registran en supportsave. El archivo supportsave lo genera un usuario administrador que soluciona problemas en el conmutador. La información registrada puede incluir nombres de usuario, contraseñas y claves secretas."
}
],
"lastModified": "2026-06-17T05:07:30.240",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:broadcom:brocade_sannav:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DC77C573-F6AD-451A-B543-682C9276861D",
"versionEndExcluding": "2.2.2"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "sirt@brocade.com"
}