BSA-2022-1977

Brocade Fabric OS

2 more products

21282

22 June 2022

22 June 2022

Closed

High

Base Score: 7.5 HIGH - Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

N/A

CVE-2022-28166

Summary

Security Advisory ID : BSA-2022-1977

Component : TLS/SSL

Revision : 1.0

In Brocade SANnav versions before v2.2.0.2, and v2.1.1.8, the implementation of TLS/SSL Server Supports the Use of Static Key Ciphers (ssl-static-key-ciphers) on ports 443 & 18082.

Affected Products

  • Brocade SANnav versions before v2.2.0.2 and v2.1.1.8 on port 443 & 18082

Products Confirmed Not Vulnerable

  • Brocade Fabric OS
  • Brocade ASCG

No other Brocade Fibre Channel Products from Broadcom are affected by this vulnerability.

Solution

A security update has been provided in Brocade SANnav v2.2.0.2 and Brocade SANnav v2.1.1.8 on ports 443 & 18082, and upper Brocade SANnav releases.

Credit

The issue was discovered during internal testing

Revision History

VersionChangeDate
1.0Initial PublicationJune 22, 2022