SANnav
by Brocade
CVEs (68)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-6392 | Med | 0.29 | 4.4 | 0.00 | Jul 10, 2025 | Brocade SANnav before Brocade SANnav 2.4.0a could log database passwords in clear text in audit logs when the daily data dump collector invokes docker exec commands. These audit logs are the local server VM’s audit logs and are not controlled by SANnav. These logs are only… | ||
| CVE-2025-6390 | Med | 0.29 | 4.4 | 0.00 | Jul 10, 2025 | Brocade SANnav before SANnav 2.4.0a logs passwords and pbe keys in the Brocade SANnav server audit logs after installation and under specific conditions. These audit logs are the local server VM’s audit logs and are not controlled by SANnav. These logs are only visible to the… | ||
| CVE-2025-4662 | Med | 0.29 | 4.4 | 0.00 | Jul 10, 2025 | Brocade SANnav before SANnav 2.4.0a logs plaintext passphrases in the Brocade SANnav host server audit logs while executing OpenSSL command using a passphrase from the command line or while providing the passphrase through a temporary file. These audit logs are the local server… | ||
| CVE-2022-43933 | Med | 0.29 | 4.4 | 0.00 | Nov 21, 2024 | An information exposure through log file vulnerability exists in Brocade SANnav before Brocade SANnav 2.2.2, where configuration secrets are logged in supportsave. Supportsave file is generated by an admin user troubleshooting the switch. The Logged information may include… | ||
| CVE-2024-29967 | Med | 0.29 | 4.4 | 0.00 | Apr 19, 2024 | In Brocade SANnav before Brocade SANnav v2.31 and v2.3.0a, it was observed that Docker instances inside the appliance have insecure mount points, allowing reading and writing access to sensitive files. The vulnerability could allow a sudo privileged user on the host OS to read… | ||
| CVE-2024-4159 | Med | 0.28 | 4.3 | 0.01 | Apr 25, 2024 | Brocade SANnav before v2.3.0a lacks protection mechanisms on port 2377/TCP and 7946/TCP, which could allow an unauthenticated attacker to sniff the SANnav Docker information. | ||
| CVE-2022-28162 | Low | 0.21 | 3.3 | 0.00 | May 9, 2022 | Brocade SANnav before version SANnav 2.2.0 logs the REST API Authentication token in plain text. | ||
| CVE-2024-29963 | Low | 0.12 | 1.9 | 0.00 | Apr 19, 2024 | Brocade SANnav OVA before v2.3.1, and v2.3.0a, contain hardcoded TLS keys used by Docker. Note: Brocade SANnav doesn't have access to remote Docker registries. |
- risk 0.29cvss 4.4epss 0.00
Brocade SANnav before Brocade SANnav 2.4.0a could log database passwords in clear text in audit logs when the daily data dump collector invokes docker exec commands. These audit logs are the local server VM’s audit logs and are not controlled by SANnav. These logs are only…
- risk 0.29cvss 4.4epss 0.00
Brocade SANnav before SANnav 2.4.0a logs passwords and pbe keys in the Brocade SANnav server audit logs after installation and under specific conditions. These audit logs are the local server VM’s audit logs and are not controlled by SANnav. These logs are only visible to the…
- risk 0.29cvss 4.4epss 0.00
Brocade SANnav before SANnav 2.4.0a logs plaintext passphrases in the Brocade SANnav host server audit logs while executing OpenSSL command using a passphrase from the command line or while providing the passphrase through a temporary file. These audit logs are the local server…
- risk 0.29cvss 4.4epss 0.00
An information exposure through log file vulnerability exists in Brocade SANnav before Brocade SANnav 2.2.2, where configuration secrets are logged in supportsave. Supportsave file is generated by an admin user troubleshooting the switch. The Logged information may include…
- risk 0.29cvss 4.4epss 0.00
In Brocade SANnav before Brocade SANnav v2.31 and v2.3.0a, it was observed that Docker instances inside the appliance have insecure mount points, allowing reading and writing access to sensitive files. The vulnerability could allow a sudo privileged user on the host OS to read…
- risk 0.28cvss 4.3epss 0.01
Brocade SANnav before v2.3.0a lacks protection mechanisms on port 2377/TCP and 7946/TCP, which could allow an unauthenticated attacker to sniff the SANnav Docker information.
- risk 0.21cvss 3.3epss 0.00
Brocade SANnav before version SANnav 2.2.0 logs the REST API Authentication token in plain text.
- risk 0.12cvss 1.9epss 0.00
Brocade SANnav OVA before v2.3.1, and v2.3.0a, contain hardcoded TLS keys used by Docker. Note: Brocade SANnav doesn't have access to remote Docker registries.
Page 4 of 4