SANnav
CVEs (26)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-15378 | Med | 0.35 | 5.3 | 0.01 | Jun 9, 2021 | The OVA version of Brocade SANnav before version 2.1.1 installation with IPv6 networking exposes the docker container ports to the network, increasing the potential attack surface. | ||
| CVE-2020-15384 | Med | 0.34 | 5.3 | 0.01 | Jun 9, 2021 | Brocade SANNav before version 2.1.1 contains an information disclosure vulnerability. Successful exploitation of internal server information in the initial login response header. | ||
| CVE-2025-12772 | Med | 0.32 | 4.9 | 0.00 | Feb 2, 2026 | Brocade SANnav before 2.4.0b logs the Brocade Fabric OS Switch admin password on the SANnav support save logs. When OOM occurs on a Brocade SANnav server, the call stack trace for the Brocade switch is also collected in the heap dump file which contains this switch password in… | ||
| CVE-2025-12680 | Med | 0.32 | 4.9 | 0.00 | Feb 2, 2026 | Brocade SANnav before Brocade SANnav 2.4.0b logs database passwords in clear text in the standby SANnav server, after disaster recovery failover. The vulnerability could allow a remote authenticated attacker with admin privilege able to access the SANnav logs or the supportsave… | ||
| CVE-2025-1053 | Med | 0.32 | 4.9 | 0.00 | Feb 14, 2025 | Under certain error conditions at time of SANnav installation or upgrade, the encryption key can be written into and obtained from a Brocade SANnav supportsave. An attacker with privileged access to the Brocade SANnav database could use the encryption key to obtain passwords… | ||
| CVE-2022-28162 | Low | 0.21 | 3.3 | 0.00 | May 9, 2022 | Brocade SANnav before version SANnav 2.2.0 logs the REST API Authentication token in plain text. |
- risk 0.35cvss 5.3epss 0.01
The OVA version of Brocade SANnav before version 2.1.1 installation with IPv6 networking exposes the docker container ports to the network, increasing the potential attack surface.
- risk 0.34cvss 5.3epss 0.01
Brocade SANNav before version 2.1.1 contains an information disclosure vulnerability. Successful exploitation of internal server information in the initial login response header.
- risk 0.32cvss 4.9epss 0.00
Brocade SANnav before 2.4.0b logs the Brocade Fabric OS Switch admin password on the SANnav support save logs. When OOM occurs on a Brocade SANnav server, the call stack trace for the Brocade switch is also collected in the heap dump file which contains this switch password in…
- risk 0.32cvss 4.9epss 0.00
Brocade SANnav before Brocade SANnav 2.4.0b logs database passwords in clear text in the standby SANnav server, after disaster recovery failover. The vulnerability could allow a remote authenticated attacker with admin privilege able to access the SANnav logs or the supportsave…
- risk 0.32cvss 4.9epss 0.00
Under certain error conditions at time of SANnav installation or upgrade, the encryption key can be written into and obtained from a Brocade SANnav supportsave. An attacker with privileged access to the Brocade SANnav database could use the encryption key to obtain passwords…
- risk 0.21cvss 3.3epss 0.00
Brocade SANnav before version SANnav 2.2.0 logs the REST API Authentication token in plain text.
Page 2 of 2