Brocade Sannav vulnerabilities

11 known vulnerabilities affecting brocade/sannav.

Total CVEs
11
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH3MEDIUM7

Vulnerabilities

Page 1 of 1
CVE-2025-12773HIGHCVSS 7.1vbefore 2.4.0a2026-02-03
CVE-2025-12773 [HIGH] CWE-209 CVE-2025-12773: A vulnerability in update-reports-purge-settings.sh script logging for Brocade SANnav before 2.4.0a A vulnerability in update-reports-purge-settings.sh script logging for Brocade SANnav before 2.4.0a could allow the collection of SANnav database password in the system audit logs. The vulnerability could allow a remote authenticated attacker with access to the audit logs to access the Brocade SANnav database password.
cvelistv5nvd
CVE-2025-12774MEDIUMCVSS 4.6vSANnav before 3.02026-02-03
CVE-2025-12774 [MEDIUM] CWE-312 CVE-2025-12774: A vulnerability in the migration script for Brocade SANnav before 3.0 could allow the collection of A vulnerability in the migration script for Brocade SANnav before 3.0 could allow the collection of database sql queries in the SANnav support save file. An attacker with access to Brocade SANnav supportsave file, could open the file and then obtain sensitive information such as details of database tables and encrypted passwords.
cvelistv5nvd
CVE-2025-12679HIGHCVSS 7.1vSANnav before 2.4.0b2026-02-02
CVE-2025-12679 [HIGH] CWE-312 CVE-2025-12679: A vulnerability in Brocade SANnav before 2.4.0b prints the Password-Based Encryption (PBE) key in p A vulnerability in Brocade SANnav before 2.4.0b prints the Password-Based Encryption (PBE) key in plaintext in the system audit log file. The vulnerability could allow a remote authenticated attacker with access to the audit logs to access the pbe key. Note: The vulnerability is only triggered during a migration and not in a new installation. The sys
cvelistv5nvd
CVE-2025-12772HIGHCVSS 8.5vbefore 2.4.0b2026-02-02
CVE-2025-12772 [HIGH] CWE-312 CVE-2025-12772: Brocade SANnav before 2.4.0b logs the Brocade Fabric OS Switch admin password on the SANnav support Brocade SANnav before 2.4.0b logs the Brocade Fabric OS Switch admin password on the SANnav support save logs. When OOM occurs on a Brocade SANnav server, the call stack trace for the Brocade switch is also collected in the heap dump file which contains this switch password in clear text. The vulnerability could allow a remote authenticated attacker w
cvelistv5nvd
CVE-2025-12680MEDIUMCVSS 6.0vbefore Brocade SANnav 2.4.0b2026-02-02
CVE-2025-12680 [MEDIUM] CWE-256 CVE-2025-12680: Brocade SANnav before Brocade SANnav 2.4.0b logs database passwords in clear text in the standby SAN Brocade SANnav before Brocade SANnav 2.4.0b logs database passwords in clear text in the standby SANnav server, after disaster recovery failover. The vulnerability could allow a remote authenticated attacker with admin privilege able to access the SANnav logs or the supportsave to read the database password.
cvelistv5nvd
CVE-2022-43937MEDIUMCVSS 5.5vBrocade SANnav before v2.3.0 and 2.2.2a2024-11-21
CVE-2022-43937 [MEDIUM] CWE-532 CVE-2022-43937: Possible information exposure through log file vulnerability where sensitive fields are recorded in Possible information exposure through log file vulnerability where sensitive fields are recorded in the debug-enabled logs when debugging is turned on in Brocade SANnav before 2.3.0 and 2.2.2a
cvelistv5nvd
CVE-2022-43936MEDIUMCVSS 4.9vbefore Brocade SANnav 2.2.22024-11-21
CVE-2022-43936 [MEDIUM] CWE-532 CVE-2022-43936: Brocade SANnav versions before 2.2.2 log Brocade Fabric OS switch passwords when debugging is enable Brocade SANnav versions before 2.2.2 log Brocade Fabric OS switch passwords when debugging is enabled.
cvelistv5nvd
CVE-2022-43933MEDIUMCVSS 4.4vbefore Brocade SANnav 2.2.22024-11-21
CVE-2022-43933 [MEDIUM] CWE-538 CVE-2022-43933: An information exposure through log file vulnerability exists in Brocade SANnav before Brocade SANna An information exposure through log file vulnerability exists in Brocade SANnav before Brocade SANnav 2.2.2, where configuration secrets are logged in supportsave. Supportsave file is generated by an admin user troubleshooting the switch. The Logged information may include usernames and passwords, and secret keys.
cvelistv5nvd
CVE-2023-31424CRITICALCVSS 9.8vBrocade SANnav before Brocade SANnav v2.3.0 and v2.2.2a2023-08-31
CVE-2023-31424 [HIGH] CWE-290 CVE-2023-31424: Brocade SANnav Web interface before Brocade SANnav v2.3.0 and v2.2.2a allows remote unauthenticated Brocade SANnav Web interface before Brocade SANnav v2.3.0 and v2.2.2a allows remote unauthenticated users to bypass web authentication and authorization.
cvelistv5nvd
CVE-2023-31423MEDIUMCVSS 5.5vBrocade SANnav before v2.3.0 and 2.2.2a2023-08-31
CVE-2023-31423 [MEDIUM] CWE-312 CVE-2023-31423: Possible information exposure through log file vulnerability where sensitive fields are recorded i Possible information exposure through log file vulnerability where sensitive fields are recorded in the configuration log without masking on Brocade SANnav before v2.3.0 and 2.2.2a. Notes: To access the logs, the local attacker must have access to an already collected Brocade SANnav "supportsave" outputs.
cvelistv5nvd
CVE-2022-28161MEDIUMCVSS 5.5fixed in 2.2.02022-05-09
CVE-2022-28161 [MEDIUM] CWE-532 CVE-2022-28161: An information exposure through log file vulnerability in Brocade SANNav versions before Brocade SAN An information exposure through log file vulnerability in Brocade SANNav versions before Brocade SANnav 2.2.0 could allow an authenticated, local attacker to view sensitive information such as ssh passwords in filetansfer.log in debug mode. To exploit this vulnerability, the attacker would need to have valid user credentials and turn on debug mode.
nvd