Broadcom / Sannav
20 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-12774 | SQL queries with sensitive information printed in logs with Brocade SANnav before 3.0 | MEDIUM | 4.6 | Feb 3, 2026 |
| CVE-2025-12773 | Plain password is generated in the audit logs while executing update-reports-purge-settings.sh script with Brocade SANnav before 2.4.0a | HIGH | 7.1 | Feb 3, 2026 |
| CVE-2025-12772 | Plaintext Switch admin login password is seen in Brocade SANnav support save | HIGH | 8.5 | Feb 2, 2026 |
| CVE-2025-12679 | Plain text pbe key visible in audit log during Brocade SANnav migration from 2.4.0a to 3.0.0 | HIGH | 7.1 | Feb 2, 2026 |
| CVE-2025-12680 | Brocade SANnav DataBase plaintext password is logged in failover logs (CVE-2025-12680) | MEDIUM | 6.0 | Feb 2, 2026 |
| CVE-2022-28168 | In Brocade SANnav before Brocade SANnav v2.2.0.2 and Brocade SANnav2.1.1.8, encoded scp-server passwords are stored using Base64 encoding, which could allow an… | HIGH | 7.5 | Jun 27, 2022 |
| CVE-2022-28167 | Brocade SANnav before Brocade SANvav v. 2.2.0.2 and Brocade SANanv v.2.1.1.8 logs the Brocade Fabric OS switch password in plain text in asyncjobscheduler-mana… | MEDIUM | 6.5 | Jun 27, 2022 |
| CVE-2022-28166 | In Brocade SANnav version before SANN2.2.0.2 and Brocade SANNav before 2.1.1.8, the implementation of TLS/SSL Server Supports the Use of Static Key Ciphers (ss… | HIGH | 7.5 | Jun 27, 2022 |
| CVE-2022-2068 | The c_rehash script allows command injection | CRITICAL | 9.8 | Jun 21, 2022 |
| CVE-2022-28162 | Brocade SANnav before version SANnav 2.2.0 logs the REST API Authentication token in plain text. | LOW | 3.3 | May 9, 2022 |
| CVE-2022-28165 | A vulnerability in the role-based access control (RBAC) functionality of the Brocade SANNav before 2.2.0 could allow an authenticated, remote attacker to acces… | HIGH | 8.8 | May 6, 2022 |
| CVE-2022-28163 | In Brocade SANnav before Brocade SANnav 2.2.0, multiple endpoints associated with Zone management are susceptible to SQL injection, allowing an attacker to run… | CRITICAL | 9.8 | May 6, 2022 |
| CVE-2022-28164 | Brocade SANnav before SANnav 2.2.0 application uses the Blowfish symmetric encryption algorithm for the storage of passwords. This could allow an authenticated… | MEDIUM | 6.5 | May 6, 2022 |
| CVE-2020-15385 | Brocade SANnav before version 2.1.1 allows an authenticated attacker to list directories, and list files without permission. As a result, users without permiss… | MEDIUM | 5.4 | Jun 9, 2021 |
| CVE-2020-15384 | Brocade SANNav before version 2.1.1 contains an information disclosure vulnerability. Successful exploitation of internal server information in the initial log… | MEDIUM | 5.3 | Jun 9, 2021 |
| CVE-2020-15380 | Brocade SANnav before version 2.1.1 logs account credentials at the ‘trace’ logging level. | HIGH | 7.5 | Jun 9, 2021 |
| CVE-2020-15378 | The OVA version of Brocade SANnav before version 2.1.1 installation with IPv6 networking exposes the docker container ports to the network, increasing the pote… | MEDIUM | 5.3 | Jun 9, 2021 |
| CVE-2020-15377 | Webtools in Brocade SANnav before version 2.1.1 allows unauthenticated users to make requests to arbitrary hosts due to a misconfiguration; this is commonly re… | CRITICAL | 9.8 | Jun 9, 2021 |
| CVE-2020-15381 | Brocade SANnav before version 2.1.1 contains an Improper Authentication vulnerability that allows cleartext transmission of authentication credentials of the j… | HIGH | 7.5 | Jun 9, 2021 |
| CVE-2020-13401 | docker: IPv6 router advertisements allow for MitM attacks | MEDIUM | 6.0 | Jun 2, 2020 |
Showing 1 to 20 of 20 CVEs