CVE-2024-2240 Details
Description
Docker daemon in Brocade SANnav before SANnav 2.3.1b runs without auditing. The vulnerability could allow a remote authenticated attacker to execute various attacks.
A vulnerability exists in the Docker daemon of Brocade SANnav versions prior to 2.3.1b, where the daemon runs without proper auditing. This lack of oversight could enable a remote authenticated attacker to execute various attacks. The Docker daemon operates with root privileges, allowing unrestricted access to the host system. Elevated operations should be audited to enhance security, facilitate incident response, and ensure compliance with standards.
Users can update to Brocade SANnav versions 2.4.0 or 2.3.1b, where this vulnerability has been addressed. Alternatively, users can manually audit Docker operations by editing the Docker audit rules file to include specific monitoring directives, then loading the new rules with the 'augenrules --load' command and validating the changes with 'auditctl -l | grep 'docker'.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 14, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25401 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-250 | Execution with Unnecessary Privileges | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| broadcom brocade sannav | < 2.3.1b |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 26, 2025 | Initial Analysis | [email protected] |
| Feb 14, 2025 | New CVE Received | [email protected] |