Brocade SANnav before v2.2.1 logs usernames and encoded passwords in debug-enabled logs
Description
Brocade SANnav before v2.2.1 logs usernames and encoded passwords in debug-enabled logs. The vulnerability could allow an attacker with admin privilege to read sensitive information.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Brocade SANnav before v2.2.1 logs usernames and encoded passwords in debug-enabled logs, allowing admin attackers to read sensitive information.
Vulnerability
Brocade SANnav versions before v2.2.1 log usernames and encoded passwords in debug-enabled logs. This occurs when debug logging is enabled, which is an administrative configuration. The affected product is Brocade SANnav, and the issue was identified internally by Broadcom.
Exploitation
An attacker with administrative privilege can exploit this vulnerability by accessing the debug logs where usernames and encoded passwords are stored. No user interaction or additional privileges are required beyond admin access to the system.
Impact
Successful exploitation allows an attacker to read usernames and encoded passwords. While the passwords are encoded, they may be susceptible to decoding or brute-force attacks, leading to further compromise. This results in high confidentiality impact and low integrity impact, as per CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N.
Mitigation
The vulnerability is fixed in Brocade SANnav version 2.2.1, released as per the advisory [1]. Users should upgrade to v2.2.1 or later. No workarounds are documented, and the CVE is not currently on the known exploited vulnerabilities (KEV) list.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <2.2.1
- Brocade/Brocade SANnavv5Range: Brocade SANnav versions before v2.2.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.