Brocade / SANnav
19 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-85417 | Incomplete property masking in the SANnav logging subsystem | MEDIUM | 6.4 | Sep 25, 2026 |
| CVE-2026-14441 | Logic flaw in SANnav Java cache key handling object comparison handling | MEDIUM | 6.9 | Sep 24, 2026 |
| CVE-2026-14442 | Information exposure vulnerability in the job scheduling component of SANnav before 3.0.1a | MEDIUM | 6.9 | Sep 24, 2026 |
| CVE-2026-14443 | Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav before 3.0.1a | HIGH | 8.4 | Sep 24, 2026 |
| CVE-2026-82372 | Improper handling of sensitive data during IPsec policy creation and modification in Brocade SANnav before 3.0.1.a | HIGH | 8.5 | Sep 24, 2026 |
| CVE-2026-82371 | Plaintext exposure of sensitive authentication data in SANnav discovery service log files | HIGH | 8.5 | Sep 24, 2026 |
| CVE-2026-82370 | Unauthenticated remote command injection in the Brocade SANnav orchestrator HTTP service | HIGH | 8.6 | Sep 23, 2026 |
| CVE-2026-82369 | Insufficient input sanitization of shell metacharacters in Brocade SANnav before 3.0.1a | HIGH | 8.6 | Sep 23, 2026 |
| CVE-2026-82368 | Insecure access controls on internal service ports in Brocade SANnav versions before 3.0.1a allow local, non-administrative host users to communicate directly… | HIGH | 8.7 | Sep 23, 2026 |
| CVE-2025-12774 | SQL queries with sensitive information printed in logs with Brocade SANnav before 3.0 | MEDIUM | 4.6 | Feb 3, 2026 |
| CVE-2025-12773 | Plain password is generated in the audit logs while executing update-reports-purge-settings.sh script with Brocade SANnav before 2.4.0a | HIGH | 7.1 | Feb 3, 2026 |
| CVE-2025-12772 | Plaintext Switch admin login password is seen in Brocade SANnav support save | HIGH | 8.5 | Feb 2, 2026 |
| CVE-2025-12679 | Plain text pbe key visible in audit log during Brocade SANnav migration from 2.4.0a to 3.0.0 | HIGH | 7.1 | Feb 2, 2026 |
| CVE-2025-12680 | Brocade SANnav DataBase plaintext password is logged in failover logs (CVE-2025-12680) | MEDIUM | 6.0 | Feb 2, 2026 |
| CVE-2022-43937 | Brocade SANnav Information Disclosure Vulnerability | MEDIUM | 5.7 | Nov 21, 2024 |
| CVE-2022-43936 | Brocade Fabric OS switch passwords when debugging is enabled | MEDIUM | 6.8 | Nov 21, 2024 |
| CVE-2022-43933 | configuration secrets are logged in support-save | MEDIUM | 4.4 | Nov 21, 2024 |
| CVE-2024-2860 | The PostgreSQL implementation in Brocade SANnav versions before 2.3.0a is vulnerable to an incorrect local authentication flaw. An attacker accessing the VM wh… | HIGH | 7.8 | May 8, 2024 |
| CVE-2024-4173 | SANnav versions exposes Kafka in the wan interface. | CRITICAL | 9.8 | Apr 25, 2024 |
| CVE-2024-29969 | TLS/SSL weak message authentication code ciphers are added by default for port 18082 | HIGH | 7.5 | Apr 19, 2024 |
| CVE-2024-29967 | In Brocade SANnav before v2.31 and v2.3.0a, it was observed that Docker instances inside the appliance have insecure mount points | MEDIUM | 6.0 | Apr 19, 2024 |
| CVE-2024-29966 | hard-coded credentials in the documentation that appear as the appliance root password | CRITICAL | 9.8 | Apr 19, 2024 |
| CVE-2024-29965 | Insecure backup | MEDIUM | 6.8 | Apr 19, 2024 |
| CVE-2024-29964 | Brocade SANnav versions before v2.3.0a do not correctly set permissions on files, including docker files | MEDIUM | 6.5 | Apr 19, 2024 |
| CVE-2024-29962 | Insecure file permission setting that makes files world-readable | MEDIUM | 5.5 | Apr 19, 2024 |
Showing 1 to 19 of 19 CVEs