VYPR
Unrated severityNVD Advisory· Published Aug 31, 2023· Updated Feb 13, 2025

Web authentication and authorization bypass

CVE-2023-31424

Description

Brocade SANnav Web interface before Brocade SANnav v2.3.0 and v2.2.2a allows remote unauthenticated users to bypass web authentication and authorization.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Brocade SANnav Web interface before v2.3.0 and v2.2.2a allows remote unauthenticated users to bypass authentication and authorization, gaining full administrative access.

Vulnerability

A web authentication and authorization bypass vulnerability exists in the Brocade SANnav Web interface. Versions before Brocade SANnav v2.3.0 and v2.2.2a are affected. The flaw allows remote unauthenticated users to bypass the authentication and authorization checks that normally protect the web GUI, gaining unintended access to administrative functions [1].

Exploitation

An attacker with network access to the Brocade SANnav web interface can exploit this vulnerability without any prior authentication. No user interaction or special privileges are required. The attacker simply sends crafted requests to the web server that circumvent the normal login and authorization enforcement [1].

Impact

Successful exploitation grants the attacker full administrative control over the Brocade SANnav appliance. This can lead to complete compromise of confidentiality (access to sensitive data), integrity (modification of configurations or data), and availability (potential disruption of services). The CVSS v3.1 base score is 8.1 (High) with the vector AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H [1].

Mitigation

Broadcom has released fixed versions: Brocade SANnav v2.3.0 and v2.2.2a. Users should upgrade to one of these versions to remediate the vulnerability. No workaround is provided in the advisory [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.