VYPR

Vendor CVEs

Brocade

All CVEs

185 total · sorted by risk
  • CVE-2018-6447MedSep 25, 2020
    risk 0.35cvss 5.4epss 0.01

    A Reflective XSS Vulnerability in HTTP Management Interface in Brocade Fabric OS versions before Brocade Fabric OS v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, v7.4.2g could allow authenticated attackers with access to the web interface to hijack a user’s session and take…

  • CVE-2024-10405MedFeb 15, 2025
    risk 0.34cvss 5.3epss 0.00

    Brocade SANnav before SANnav 2.3.1b enables weak TLS ciphers on ports 443 and 18082. In case of a successful exploit, an attacker can read Brocade SANnav data stream that includes monitored Brocade Fabric OS switches performance data, port status, zoning information, WWNs,…

  • CVE-2022-43935MedNov 21, 2024
    risk 0.34cvss 5.3epss 0.00

    An information exposure through log file vulnerability exists in Brocade SANnav before Brocade SANnav 2.2.2, where Brocade Fabric OS Switch passwords and authorization IDs are printed in the embedded MLS DB file.

  • CVE-2023-31927MedAug 2, 2023
    risk 0.34cvss 5.3epss 0.01

    An information disclosure in the web interface of Brocade Fabric OS versions before Brocade Fabric OS v9.2.0 and v9.1.1c, could allow a remote unauthenticated attacker to get technical details about the web interface.

  • CVE-2020-15384MedJun 9, 2021
    risk 0.34cvss 5.3epss 0.01

    Brocade SANNav before version 2.1.1 contains an information disclosure vulnerability. Successful exploitation of internal server information in the initial login response header.

  • CVE-2024-29955MedApr 17, 2024
    risk 0.33cvss 5.0epss 0.00

    A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow a privileged user to print the SANnav encrypted key in PostgreSQL startup logs. This could provide attackers with an additional, less-protected path to acquiring the encryption key.

  • CVE-2025-12772MedFeb 2, 2026
    risk 0.32cvss 4.9epss 0.00

    Brocade SANnav before 2.4.0b logs the Brocade Fabric OS Switch admin password on the SANnav support save logs. When OOM occurs on a Brocade SANnav server, the call stack trace for the Brocade switch is also collected in the heap dump file which contains this switch password in…

  • CVE-2025-12680MedFeb 2, 2026
    risk 0.32cvss 4.9epss 0.00

    Brocade SANnav before Brocade SANnav 2.4.0b logs database passwords in clear text in the standby SANnav server, after disaster recovery failover. The vulnerability could allow a remote authenticated attacker with admin privilege able to access the SANnav logs or the supportsave…

  • CVE-2025-4663MedJul 8, 2025
    risk 0.32cvss 4.9epss 0.00

    An Improper Check for Unusual or Exceptional Conditions vulnerability in Brocade Fabric OS before 9.2.2.a could allow an authenticated, network-based attacker to cause a Denial-of-Service (DoS). The vulnerability is encountered when supportsave is invoked remotely, using…

  • CVE-2025-1053MedFeb 14, 2025
    risk 0.32cvss 4.9epss 0.00

    Under certain error conditions at time of SANnav installation or upgrade, the encryption key can be written into and obtained from a Brocade SANnav supportsave. An attacker with privileged access to the Brocade SANnav database could use the encryption key to obtain passwords…

  • CVE-2025-6392MedJul 10, 2025
    risk 0.29cvss 4.4epss 0.00

    Brocade SANnav before Brocade SANnav 2.4.0a could log database passwords in clear text in audit logs when the daily data dump collector invokes docker exec commands. These audit logs are the local server VM’s audit logs and are not controlled by SANnav. These logs are only…

  • CVE-2025-6390MedJul 10, 2025
    risk 0.29cvss 4.4epss 0.00

    Brocade SANnav before SANnav 2.4.0a logs passwords and pbe keys in the Brocade SANnav server audit logs after installation and under specific conditions. These audit logs are the local server VM’s audit logs and are not controlled by SANnav. These logs are only visible to the…

  • CVE-2025-4662MedJul 10, 2025
    risk 0.29cvss 4.4epss 0.00

    Brocade SANnav before SANnav 2.4.0a logs plaintext passphrases in the Brocade SANnav host server audit logs while executing OpenSSL command using a passphrase from the command line or while providing the passphrase through a temporary file. These audit logs are the local server…

  • CVE-2022-43933MedNov 21, 2024
    risk 0.29cvss 4.4epss 0.00

    An information exposure through log file vulnerability exists in Brocade SANnav before Brocade SANnav 2.2.2, where configuration secrets are logged in supportsave. Supportsave file is generated by an admin user troubleshooting the switch. The Logged information may include…

  • CVE-2024-29967MedApr 19, 2024
    risk 0.29cvss 4.4epss 0.00

    In Brocade SANnav before Brocade SANnav v2.31 and v2.3.0a, it was observed that Docker instances inside the appliance have insecure mount points, allowing reading and writing access to sensitive files. The vulnerability could allow a sudo privileged user on the host OS to read…

  • CVE-2023-4163MedAug 31, 2023
    risk 0.29cvss 4.4epss 0.00

    In Brocade Fabric OS before v9.2.0a, a local authenticated privileged user can trigger a buffer overflow condition, leading to a kernel panic with large input to buffers in the portcfgfportbuffers command.

  • CVE-2023-4162MedAug 31, 2023
    risk 0.29cvss 4.4epss 0.00

    A segmentation fault can occur in Brocade Fabric OS after Brocade Fabric OS v9.0 and before Brocade Fabric OS v9.2.0a through the passwdcfg command. This could allow an authenticated privileged user local user to crash a Brocade Fabric OS swith using the cli “passwdcfg…

  • CVE-2024-29953MedJun 26, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability in the web interface in Brocade Fabric OS before v9.2.1, v9.2.0b, and v9.1.1d prints encoded session passwords on session storage for Virtual Fabric platforms. This could allow an authenticated user to view other users' session encoded passwords.

  • CVE-2024-4159MedApr 25, 2024
    risk 0.28cvss 4.3epss 0.01

    Brocade SANnav before v2.3.0a lacks protection mechanisms on port 2377/TCP and 7946/TCP, which could allow an unauthenticated attacker to sniff the SANnav Docker information.

  • CVE-2023-5973MedApr 5, 2024
    risk 0.28cvss 4.3epss 0.00

    Brocade Web Interface in Brocade Fabric OS v9.x and before v9.2.0 does not properly represent the portName to the user if the portName contains reserved characters. This could allow an authenticated user to alter the UI of the Brocade Switch and change ports display.

  • CVE-2020-15376MedDec 11, 2020
    risk 0.28cvss 4.3epss 0.01

    Brocade Fabric OS versions before v9.0.0 and after version v8.1.0, configured in Virtual Fabric mode contain a weakness in the ldap implementation that could allow a remote ldap user to login in the Brocade Fibre Channel SAN switch with "user" privileges if it is not associated…

  • CVE-2022-28162LowMay 9, 2022
    risk 0.21cvss 3.3epss 0.00

    Brocade SANnav before version SANnav 2.2.0 logs the REST API Authentication token in plain text.

  • CVE-2021-22555HigKEVJul 7, 2021
    risk 0.21cvss 8.3epss 0.79

    A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space

  • CVE-2025-58381LowFeb 3, 2026
    risk 0.15cvss 2.3epss 0.00

    A vulnerability in Brocade Fabric OS before 9.2.1c2 could allow an authenticated attacker with admin privileges using the shell commands “source, ping6, sleep, disown, wait to modify the path variables and move upwards in the directory structure or to traverse to different…

  • CVE-2025-58380LowFeb 3, 2026
    risk 0.15cvss 2.3epss 0.00

    A vulnerability in Brocade Fabric OS before 9.2.1 could allow an authenticated attacker with admin privileges using the shell command “grep” to modify the path variables and move upwards in the directory structure or to traverse to different directories.

  • CVE-2025-4661LowJun 19, 2025
    risk 0.15cvss 2.3epss 0.00

    A path transversal vulnerability in Brocade Fabric OS 9.1.0 through 9.2.2 could allow a local admin user to gain access to files outside the intended directory potentially leading to the disclosure of sensitive information. Note: Admin level privilege is required on the…

  • CVE-2024-29963LowApr 19, 2024
    risk 0.12cvss 1.9epss 0.00

    Brocade SANnav OVA before v2.3.1, and v2.3.0a, contain hardcoded TLS keys used by Docker. Note: Brocade SANnav doesn't have access to remote Docker registries.

  • CVE-2013-6810Dec 12, 2013
    risk 0.04cvss —epss 0.17

    The server in Brocade Network Advisor before 12.1.0, as used in EMC Connectrix Manager Converged Network Edition (CMCNE), HP B-series SAN Network Advisor, and possibly other products, allows remote attackers to execute arbitrary code by using a servlet to upload an executable…

  • CVE-2014-4870Oct 7, 2014
    risk 0.00cvss —epss 0.00

    /opt/vyatta/bin/sudo-users/vyatta-clear-dhcp-lease.pl on the Brocade Vyatta 5400 vRouter 6.4R(x), 6.6R(x), and 6.7R1 does not properly validate parameters, which allows local users to gain privileges by leveraging the sudo configuration.

  • CVE-2014-4869Oct 7, 2014
    risk 0.00cvss —epss 0.01

    The Brocade Vyatta 5400 vRouter 6.4R(x), 6.6R(x), and 6.7R1 allows attackers to obtain sensitive encrypted-password information by leveraging membership in the operator group.

  • CVE-2014-4868Oct 7, 2014
    risk 0.00cvss —epss 0.03

    The management console on the Brocade Vyatta 5400 vRouter 6.4R(x), 6.6R(x), and 6.7R1 allows remote authenticated users to execute arbitrary Linux commands via shell metacharacters in a console command.

  • CVE-2013-7307Jan 23, 2014
    risk 0.00cvss —epss 0.01

    The OSPF implementation on the Brocade Vyatta vRouter with software before 6.6R1 does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause…

  • CVE-2013-7306Jan 23, 2014
    risk 0.00cvss —epss 0.01

    The OSPF implementation on Brocade routers does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing…

  • CVE-2011-2760Jul 17, 2011
    risk 0.00cvss —epss 0.02

    Brocade BigIron RX switches allow remote attackers to bypass ACL rules by using 179 as the source port of a packet.

  • CVE-2004-1663Sep 4, 2004
    risk 0.00cvss —epss 0.04

    Engenio/LSI Logic storage controllers, as used in products such as Storagetek D280, and IBM DS4100 (formerly FastT 100) and Brocade SilkWorm Switches, allow remote attackers to cause a denial of service (freeze and possible data corruption) via crafted TCP packets.

Page 4 of 4