Impact
The vulnerability lies in the incomplete sanitization of logs during bulk IPsec policy collection in Brocade SANnav versions prior to 3.0.1a. The system writes pre‑shared keys to container logs and support archives, allowing a user with read access to these logs to obtain the keys and compromise the confidentiality of encrypted network tunnels. This is a log data disclosure weakness (CWE‑532).
Affected Systems
Brocade SANnav firmware versions earlier than 3.0.1a are affected. The flaw exists in any installation that uses the bulk IPsec policy collection feature.
Risk and Exploitability
The CVSS score of 8.4 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, implying no currently known public exploits. Exploitation requires legitimate file‑system read access to container logs or support archives, limiting the threat to users with such permissions or to compromised administrators. Nevertheless, the leakage of pre‑shared keys could enable an attacker to decrypt or forge IPsec traffic, posing a significant confidentiality risk. Based on the description, it is inferred that the attacker’s necessary permission is read access to container logs or support archives.
OpenCVE Enrichment