---
cve: "CVE-2024-10405"
severity: "MEDIUM"
cvss: 6.9
epss: "0.2%"
vendor: "Brocade"
kev: false
exploited: false
published: "2025-02-14 23:23:18"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-20T20:06:11+02:00"
---

# CVE-2024-10405

> 6.9 MEDIUM

## Beschreibung

Brocade SANnav before SANnav 2.3.1b 
enables weak TLS ciphers on ports 443 and 18082. In case of a successful
 exploit, an attacker can read Brocade SANnav data stream that includes 
monitored Brocade Fabric OS switches performance data, port status, 
zoning information, WWNs, IP Addresses, but no customer data, no 
personal data and no secrets or passwords, as it travels across the 
network.

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |

## Referenzen

- <https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25402>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2024-10405) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
