VYPR

SANnav

by Brocade

CVEs (73)

  • CVE-2024-4282CriFeb 15, 2025
    risk 0.64cvss 9.8epss 0.00

    Brocade SANnav OVA before SANnav 2.3.1b enables SHA1 deprecated setting for SSH for port 22.

  • CVE-2022-28163CriMay 6, 2022
    risk 0.64cvss 9.8epss 0.01

    In Brocade SANnav before Brocade SANnav 2.2.0, multiple endpoints associated with Zone management are susceptible to SQL injection, allowing an attacker to run arbitrary SQL commands.

  • CVE-2020-15377CriJun 9, 2021
    risk 0.64cvss 9.8epss 0.01

    Webtools in Brocade SANnav before version 2.1.1 allows unauthenticated users to make requests to arbitrary hosts due to a misconfiguration; this is commonly referred to as Server-Side Request Forgery (SSRF).

  • CVE-2019-16211CriSep 25, 2020
    risk 0.64cvss 9.8epss 0.01

    Brocade SANnav versions before v2.1.0, contain a Plaintext Password Storage vulnerability.

  • CVE-2026-82368HigSep 23, 2026
    risk 0.57cvss —epss 0.00

    Insecure access controls on internal service ports in Brocade SANnav versions before 3.0.1a allow local, non-administrative host users to communicate directly with backend management services. A local attacker can leverage this exposed access to transmit commands to connected…

  • CVE-2022-28165HigMay 6, 2022
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the role-based access control (RBAC) functionality of the Brocade SANNav before 2.2.0 could allow an authenticated, remote attacker to access resources that they should not be able to access and perform actions that they should not be able to perform. The…

  • CVE-2019-16212HigSep 25, 2020
    risk 0.57cvss 8.8epss 0.02

    A vulnerability in Brocade SANnav versions before v2.1.0 could allow a remote authenticated attacker to conduct an LDAP injection. The vulnerability could allow a remote attacker to bypass the authentication process.

  • CVE-2019-16205HigNov 8, 2019
    risk 0.57cvss 8.8epss 0.01

    A vulnerability, in Brocade SANnav versions before v2.0, could allow remote attackers to brute-force a valid session ID. The vulnerability is due to an insufficiently random session ID for several post-authentication actions in the SANnav portal.

  • CVE-2026-82369HigSep 23, 2026
    risk 0.56cvss —epss 0.01

    Insufficient input sanitization of shell metacharacters in the Brocade SANnav CLI scripting component permits authenticated users to break out of restricted execution contexts on managed switches. An attacker with command execution permissions can leverage this flaw to run…

  • CVE-2024-4161HigApr 25, 2024
    risk 0.56cvss 8.6epss 0.00

    In Brocade SANnav, before Brocade SANnav v2.3.0, syslog traffic received clear text. This could allow an unauthenticated, remote attacker to capture sensitive information.

  • CVE-2024-29959HigApr 19, 2024
    risk 0.56cvss 8.6epss 0.00

    A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints Brocade Fabric OS switch encrypted passwords in the Brocade SANnav Standby node's support save.

  • CVE-2026-14443HigSep 24, 2026
    risk 0.55cvss —epss 0.00

    Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav versions before 3.0.1a permit extension switch pre-shared keys to be written to system logs. Individuals with read access to container logs or support archives can obtain these keys, leading to the…

  • CVE-2026-82372HigSep 24, 2026
    risk 0.55cvss —epss 0.00

    Improper handling of sensitive data during IPsec policy creation and modification in Brocade SANnav versions before 3.0.1a results in pre-shared keys being recorded in application logs. Individuals with read access to system log files or support bundles can view these…

  • CVE-2026-82371HigSep 24, 2026
    risk 0.55cvss —epss 0.00

    Plaintext exposure of sensitive authentication data in Brocade SANnav discovery service log files enables individuals with file read access to retrieve administrative switch credentials and active session tokens. An attacker with access to system logs or support bundles can…

  • CVE-2024-29961HigApr 19, 2024
    risk 0.53cvss 8.2epss 0.01

    A vulnerability affects Brocade SANnav before v2.3.1 and v2.3.0a. It allows a Brocade SANnav service to send ping commands in the background at regular intervals to gridgain.com to check if updates are available for the Component. This could make an unauthenticated, remote…

  • CVE-2023-31424HigAug 31, 2023
    risk 0.53cvss 8.1epss 0.01

    Brocade SANnav Web interface before Brocade SANnav v2.3.0 and v2.2.2a allows remote unauthenticated users to bypass web authentication and authorization.

  • CVE-2024-2860HigMay 8, 2024
    risk 0.51cvss 7.8epss 0.00

    The PostgreSQL implementation in Brocade SANnav versions before 2.3.0a is vulnerable to an incorrect local authentication flaw. An attacker accessing the VM where the Brocade SANnav is installed can gain access to sensitive data inside the PostgreSQL database.

  • CVE-2019-16207HigNov 8, 2019
    risk 0.51cvss 7.8epss 0.00

    Brocade SANnav versions before v2.0 use a hard-coded password, which could allow local authenticated attackers to access a back-end database and gain privileges.

  • CVE-2024-29968HigApr 19, 2024
    risk 0.50cvss 7.7epss 0.00

    An information disclosure vulnerability exists in Brocade SANnav before v2.3.1 and v2.3.0a when Brocade SANnav instances are configured in disaster recovery mode. SQL Table names, column names, and SQL queries are collected in DR standby Supportsave. This could allow…

  • CVE-2025-12774HigFeb 3, 2026
    risk 0.49cvss 7.5epss 0.00

    A vulnerability in the migration script for Brocade SANnav before 3.0 could allow the collection of database sql queries in the SANnav support save file. An attacker with access to Brocade SANnav supportsave file, could open the file and then obtain sensitive information such…

Page 1 of 4