VYPR

Brocade Sannav

by Broadcom Corporation

CVEs (59)

  • CVE-2024-29950HigApr 17, 2024
    risk 0.49cvss 7.5epss 0.00

    The class FileTransfer implemented in Brocade SANnav before v2.3.1, v2.3.0a, uses the ssh-rsa signature scheme, which has a SHA-1 hash. The vulnerability could allow a remote, unauthenticated attacker to perform a man-in-the-middle attack.

  • CVE-2020-15379HigJun 9, 2021
    risk 0.49cvss 7.5epss 0.01

    Brocade SANnav before v.2.1.0a could allow remote attackers cause a denial-of-service condition due to a lack of proper validation, of the length of user-supplied data as name for custom field name.

  • CVE-2019-16208HigNov 8, 2019
    risk 0.49cvss 7.5epss 0.00

    Password-based encryption (PBE) algorithm, of Brocade SANnav versions before v2.0, has a weakness in generating cryptographic keys that may allow an attacker to decrypt passwords used with several services (Radius, TACAS, etc.).

  • CVE-2020-15387HigJun 9, 2021
    risk 0.48cvss 7.4epss 0.00

    The host SSH servers of Brocade Fabric OS before Brocade Fabric OS v7.4.2h, v8.2.1c, v8.2.2, v9.0.0, and Brocade SANnav before v2.1.1 utilize keys of less than 2048 bits, which may be vulnerable to man-in-the-middle attacks and/or insecure SSH communications.

  • CVE-2019-16209HigNov 8, 2019
    risk 0.48cvss 7.4epss 0.01

    A vulnerability, in The ReportsTrustManager class of Brocade SANnav versions before v2.0, could allow an attacker to perform a man-in-the-middle attack against Secure Sockets Layer(SSL)connections.

  • CVE-2024-2240HigFeb 14, 2025
    risk 0.47cvss 7.2epss 0.01

    Docker daemon in Brocade SANnav before SANnav 2.3.1b runs without auditing. The vulnerability could allow a remote authenticated attacker to execute various attacks.

  • CVE-2020-15382HigJun 9, 2021
    risk 0.47cvss 7.2epss 0.01

    Brocade SANnav before version 2.1.1 uses a hard-coded administrator account with the weak password ‘passw0rd’ if a password is not provided for PostgreSQL at install-time.

  • CVE-2022-43936MedNov 21, 2024
    risk 0.44cvss 6.8epss 0.01

    Brocade SANnav versions before 2.2.2 log Brocade Fabric OS switch passwords when debugging is enabled.

  • CVE-2024-2859MedApr 27, 2024
    risk 0.44cvss 6.8epss 0.01

    By default, SANnav OVA is shipped with root user login enabled. While protected by a password, access to root could expose SANnav to a remote attacker should they gain access to the root account.

  • CVE-2024-29965MedApr 19, 2024
    risk 0.44cvss 6.8epss 0.00

    In Brocade SANnav before v2.3.1, and v2.3.0a, it is possible to back up the appliance from the web interface or the command line interface ("SSH"). The resulting backups are world-readable. A local attacker can recover backup files, restore them to a new malicious appliance,…

  • CVE-2024-29960MedApr 19, 2024
    risk 0.44cvss 6.8epss 0.00

    In Brocade SANnav server before v2.3.1 and v2.3.0a, the SSH keys inside the OVA image are identical in the VM every time SANnav is installed. Any Brocade SAnnav VM based on the official OVA images is vulnerable to MITM over SSH. An attacker can decrypt and compromise the SSH…

  • CVE-2022-43934MedNov 21, 2024
    risk 0.42cvss 6.5epss 0.00

    Brocade SANnav before Brocade SANnav 2.2.2 supports key exchange algorithms, which are considered weak on ports 24, 6514, 18023, 19094, and 19095.

  • CVE-2024-29956MedApr 18, 2024
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints the Brocade SANnav password in clear text in supportsave logs when a user schedules a switch Supportsave from Brocade SANnav.

  • CVE-2022-28164MedMay 6, 2022
    risk 0.42cvss 6.5epss 0.00

    Brocade SANnav before SANnav 2.2.0 application uses the Blowfish symmetric encryption algorithm for the storage of passwords. This could allow an authenticated attacker to decrypt stored account passwords.

  • CVE-2022-43937MedNov 21, 2024
    risk 0.37cvss 5.7epss 0.00

    Possible information exposure through log file vulnerability where sensitive fields are recorded in the debug-enabled logs when debugging is turned on in Brocade SANnav before 2.3.0 and 2.2.2a

  • CVE-2024-29964MedApr 19, 2024
    risk 0.37cvss 5.7epss 0.01

    Brocade SANnav versions before v2.3.0a do not correctly set permissions on files, including docker files. An unprivileged attacker who gains access to the server can read sensitive information from these files.

  • CVE-2024-29951MedApr 17, 2024
    risk 0.37cvss 5.7epss 0.00

    Brocade SANnav before v2.3.1 and v2.3.0a uses the SHA-1 hash in internal SSH ports that are not open to remote connection.

  • CVE-2023-31423MedAug 31, 2023
    risk 0.37cvss 5.7epss 0.00

    Possible information exposure through log file vulnerability where sensitive fields are recorded in the configuration log without masking on Brocade SANnav before v2.3.0 and 2.2.2a. Notes: To access the logs, the local attacker must have access to an already collected…

  • CVE-2024-10404MedFeb 14, 2025
    risk 0.36cvss 5.5epss 0.00

    CalInvocationHandler in Brocade SANnav before 2.3.1b logs sensitive information in clear text. The vulnerability could allow an authenticated, local attacker to view Brocade Fabric OS switch sensitive information in clear text. An attacker with administrative privileges…

  • CVE-2024-29962MedApr 19, 2024
    risk 0.36cvss 5.5epss 0.00

    Brocade SANnav OVA before v2.3.1 and v2.3.0a have an insecure file permission setting that makes files world-readable. This could allow a local user without the required privileges to access sensitive information or a Java binary.