VYPR

SANnav

by Broadcom Corporation

CVEs (26)

  • CVE-2022-28163CriMay 6, 2022
    risk 0.64cvss 9.8epss 0.01

    In Brocade SANnav before Brocade SANnav 2.2.0, multiple endpoints associated with Zone management are susceptible to SQL injection, allowing an attacker to run arbitrary SQL commands.

  • CVE-2020-15377CriJun 9, 2021
    risk 0.64cvss 9.8epss 0.01

    Webtools in Brocade SANnav before version 2.1.1 allows unauthenticated users to make requests to arbitrary hosts due to a misconfiguration; this is commonly referred to as Server-Side Request Forgery (SSRF).

  • CVE-2022-28165HigMay 6, 2022
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the role-based access control (RBAC) functionality of the Brocade SANNav before 2.2.0 could allow an authenticated, remote attacker to access resources that they should not be able to access and perform actions that they should not be able to perform. The…

  • CVE-2019-16205HigNov 8, 2019
    risk 0.57cvss 8.8epss 0.01

    A vulnerability, in Brocade SANnav versions before v2.0, could allow remote attackers to brute-force a valid session ID. The vulnerability is due to an insufficiently random session ID for several post-authentication actions in the SANnav portal.

  • CVE-2025-12774HigFeb 3, 2026
    risk 0.49cvss 7.5epss 0.00

    A vulnerability in the migration script for Brocade SANnav before 3.0 could allow the collection of database sql queries in the SANnav support save file. An attacker with access to Brocade SANnav supportsave file, could open the file and then obtain sensitive information such…

  • CVE-2024-4173HigApr 25, 2024
    risk 0.49cvss 7.6epss 0.01

    A vulnerability in Brocade SANnav exposes Kafka in the wan interface. The vulnerability could allow an unauthenticated attacker to perform various attacks, including DOS against the Brocade SANnav.

  • CVE-2024-29966HigApr 19, 2024
    risk 0.49cvss 7.5epss 0.01

    Brocade SANnav OVA before v2.3.1 and v2.3.0a contain hard-coded credentials in the documentation that appear as the appliance's root password. The vulnerability could allow an unauthenticated attacker full access to the Brocade SANnav appliance.

  • CVE-2022-28168HigJun 27, 2022
    risk 0.49cvss 7.5epss 0.01

    In Brocade SANnav before Brocade SANnav v2.2.0.2 and Brocade SANnav2.1.1.8, encoded scp-server passwords are stored using Base64 encoding, which could allow an attacker able to access log files to easily decode the passwords.

  • CVE-2022-28166HigJun 27, 2022
    risk 0.49cvss 7.5epss 0.01

    In Brocade SANnav version before SANN2.2.0.2 and Brocade SANNav before 2.1.1.8, the implementation of TLS/SSL Server Supports the Use of Static Key Ciphers (ssl-static-key-ciphers) on ports 443 & 18082.

  • CVE-2020-15380HigJun 9, 2021
    risk 0.49cvss 7.5epss 0.01

    Brocade SANnav before version 2.1.1 logs account credentials at the ‘trace’ logging level.

  • CVE-2020-15381HigJun 9, 2021
    risk 0.49cvss 7.5epss 0.01

    Brocade SANnav before version 2.1.1 contains an Improper Authentication vulnerability that allows cleartext transmission of authentication credentials of the jmx server.

  • CVE-2022-2068HigJun 21, 2022
    risk 0.48cvss 7.3epss 0.95

    In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022-1292 was fixed it was not…

  • CVE-2024-2240HigFeb 14, 2025
    risk 0.47cvss 7.2epss 0.01

    Docker daemon in Brocade SANnav before SANnav 2.3.1b runs without auditing. The vulnerability could allow a remote authenticated attacker to execute various attacks.

  • CVE-2024-29960MedApr 19, 2024
    risk 0.44cvss 6.8epss 0.00

    In Brocade SANnav server before v2.3.1 and v2.3.0a, the SSH keys inside the OVA image are identical in the VM every time SANnav is installed. Any Brocade SAnnav VM based on the official OVA images is vulnerable to MITM over SSH. An attacker can decrypt and compromise the SSH…

  • CVE-2025-12773MedFeb 3, 2026
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in update-reports-purge-settings.sh script logging for Brocade SANnav before 2.4.0a could allow the collection of SANnav database password in the system audit logs. The vulnerability could allow a remote authenticated attacker with access to the audit logs to…

  • CVE-2025-12679MedFeb 2, 2026
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in Brocade SANnav before 2.4.0b prints the Password-Based Encryption (PBE) key in plaintext in the system audit log file. The vulnerability could allow a remote authenticated attacker with access to the audit logs to access the pbe key. Note: The…

  • CVE-2022-28167MedJun 27, 2022
    risk 0.42cvss 6.5epss 0.01

    Brocade SANnav before Brocade SANvav v. 2.2.0.2 and Brocade SANanv v.2.1.1.8 logs the Brocade Fabric OS switch password in plain text in asyncjobscheduler-manager.log

  • CVE-2022-28164MedMay 6, 2022
    risk 0.42cvss 6.5epss 0.00

    Brocade SANnav before SANnav 2.2.0 application uses the Blowfish symmetric encryption algorithm for the storage of passwords. This could allow an authenticated attacker to decrypt stored account passwords.

  • CVE-2020-13401MedJun 2, 2020
    risk 0.39cvss 6.0epss 0.03

    An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements, and consequently spoof external IPv6 hosts, obtain sensitive information, or cause a denial of service.

  • CVE-2020-15385MedJun 9, 2021
    risk 0.35cvss 5.4epss 0.01

    Brocade SANnav before version 2.1.1 allows an authenticated attacker to list directories, and list files without permission. As a result, users without permission can see folders, and hidden files, and can create directories without permission.

Page 1 of 2