Description
Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav versions before 3.0.1a permit extension switch pre-shared keys to be written to system logs. Individuals with read access to container logs or support archives can obtain these keys, leading to the potential compromise of encrypted network tunnels.
Published: 2026-09-24
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Log data exposure leading to IPsec key compromise
Action: Immediate patch
AI Analysis

Impact

The vulnerability lies in the incomplete sanitization of logs during bulk IPsec policy collection in Brocade SANnav versions prior to 3.0.1a. The system writes pre‑shared keys to container logs and support archives, allowing a user with read access to these logs to obtain the keys and compromise the confidentiality of encrypted network tunnels. This is a log data disclosure weakness (CWE‑532).

Affected Systems

Brocade SANnav firmware versions earlier than 3.0.1a are affected. The flaw exists in any installation that uses the bulk IPsec policy collection feature.

Risk and Exploitability

The CVSS score of 8.4 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, implying no currently known public exploits. Exploitation requires legitimate file‑system read access to container logs or support archives, limiting the threat to users with such permissions or to compromised administrators. Nevertheless, the leakage of pre‑shared keys could enable an attacker to decrypt or forge IPsec traffic, posing a significant confidentiality risk. Based on the description, it is inferred that the attacker’s necessary permission is read access to container logs or support archives.

Generated by OpenCVE AI on September 25, 2026 at 04:21 UTC.

Remediation

Vendor Solution

Security update provided in Brocade SANnav 3.0.1a


OpenCVE Recommended Actions

  • Upgrade Brocade SANnav to version 3.0.1a or later, which sanitizes log output for IPsec policy collection.
  • After the upgrade, review and purge any existing logs that may contain pre‑shared keys to prevent residual exposure.
  • Restrict file‑system permissions on container logs, support archives, and the directory used for bulk IPsec policy collection so that only privileged administrators can read them.
  • If the bulk IPsec policy collection feature is not required, disable it to reduce the attack surface.

Generated by OpenCVE AI on September 25, 2026 at 04:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
First Time appeared Brocade
Brocade sannav
Vendors & Products Brocade
Brocade sannav

Thu, 24 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav versions before 3.0.1a permit extension switch pre-shared keys to be written to system logs. Individuals with read access to container logs or support archives can obtain these keys, leading to the potential compromise of encrypted network tunnels.
Title Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav before 3.0.1a
Weaknesses CWE-532
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published:

Updated: 2026-09-24T20:06:28.925Z

Reserved: 2026-07-01T23:05:44.125Z

Link: CVE-2026-14443

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-24T21:17:12.130

Modified: 2026-09-25T13:16:34.693

Link: CVE-2026-14443

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T06:15:16Z

Weaknesses
  • CWE-532

    Insertion of Sensitive Information into Log File