Skip to main content

Vendor/product archive

broadcom / sannav CVEs

Beta · best-effort

19 CVEs tagged to broadcom / sannav2 Critical, 8 High, 8 Medium, 1 Low, 0 Unrated.

CVE-2025-12774

Published Feb 3, 2026

A vulnerability in the migration script for Brocade SANnav before 3.0 could allow the collection of database sql queries in the SANnav support save file. An attacker with access t…

CVSS 4.6 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-12773

Published Feb 3, 2026

A vulnerability in update-reports-purge-settings.sh script logging for Brocade SANnav before 2.4.0a could allow the collection of SANnav database password in the system audit logs…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-12772

Published Feb 2, 2026

Brocade SANnav before 2.4.0b logs the Brocade Fabric OS Switch admin password on the SANnav support save logs. When OOM occurs on a Brocade SANnav server, the call stack trace fo…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-12680

Published Feb 2, 2026

Brocade SANnav before Brocade SANnav 2.4.0b logs database passwords in clear text in the standby SANnav server, after disaster recovery failover. The vulnerability could allow a…

CVSS 6.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-12679

Published Feb 2, 2026

A vulnerability in Brocade SANnav before 2.4.0b prints the Password-Based Encryption (PBE) key in plaintext in the system audit log file. The vulnerability could allow a remote…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-28168

Published Jun 27, 2022

In Brocade SANnav before Brocade SANnav v2.2.0.2 and Brocade SANnav2.1.1.8, encoded scp-server passwords are stored using Base64 encoding, which could allow an attacker able to ac…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-28167

Published Jun 27, 2022

Brocade SANnav before Brocade SANvav v. 2.2.0.2 and Brocade SANanv v.2.1.1.8 logs the Brocade Fabric OS switch password in plain text in asyncjobscheduler-manager.log

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-28166

Published Jun 27, 2022

In Brocade SANnav version before SANN2.2.0.2 and Brocade SANNav before 2.1.1.8, the implementation of TLS/SSL Server Supports the Use of Static Key Ciphers (ssl-static-key-ciphers…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-28162

Published May 9, 2022

Brocade SANnav before version SANnav 2.2.0 logs the REST API Authentication token in plain text.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-28165

Published May 6, 2022

A vulnerability in the role-based access control (RBAC) functionality of the Brocade SANNav before 2.2.0 could allow an authenticated, remote attacker to access resources that the…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-28164

Published May 6, 2022

Brocade SANnav before SANnav 2.2.0 application uses the Blowfish symmetric encryption algorithm for the storage of passwords. This could allow an authenticated attacker to decrypt…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-28163

Published May 6, 2022

In Brocade SANnav before Brocade SANnav 2.2.0, multiple endpoints associated with Zone management are susceptible to SQL injection, allowing an attacker to run arbitrary SQL comma…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-15385

Published Jun 9, 2021

Brocade SANnav before version 2.1.1 allows an authenticated attacker to list directories, and list files without permission. As a result, users without permission can see folders,…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15384

Published Jun 9, 2021

Brocade SANNav before version 2.1.1 contains an information disclosure vulnerability. Successful exploitation of internal server information in the initial login response header.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15380

Published Jun 9, 2021

Brocade SANnav before version 2.1.1 logs account credentials at the ‘trace’ logging level.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15378

Published Jun 9, 2021

The OVA version of Brocade SANnav before version 2.1.1 installation with IPv6 networking exposes the docker container ports to the network, increasing the potential attack surface.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15377

Published Jun 9, 2021

Webtools in Brocade SANnav before version 2.1.1 allows unauthenticated users to make requests to arbitrary hosts due to a misconfiguration; this is commonly referred to as Server-…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-15381

Published Jun 9, 2021

Brocade SANnav before version 2.1.1 contains an Improper Authentication vulnerability that allows cleartext transmission of authentication credentials of the jmx server.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-19 of 19 CVEsPage 1 of 1