Description
A vulnerability in Brocade SANnav before 2.4.0b and 3.0.0 prints encoded passwords and  authentication tokens in log files. The vulnerability could allow an authenticated attacker with access to the log file including the SANnav supportsave to access the passwords.
Published: 2026-10-08
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: Information Disclosure of passwords and authentication tokens
Action: Apply Patch
AI Analysis

Impact

A flaw in Brocade SANnav versions prior to 2.4.0b, 3.0.0, and 3.0.1 causes the software to write encoded passwords and authentication tokens to log files. The flaw is associated with CWE-922 and allows the compromise of credential secrecy. An attacker who can read the log files can recover credentials that are intended to remain confidential.

Affected Systems

Brocade SANnav products affected include all releases before 2.4.0b and before 3.0.0. Users should verify whether they are running these unpatched versions.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.2, indicating high severity. EPSS data is unavailable, and the vulnerability is not listed in CISA KEV. Exploitation requires that the attacker be authenticated to the system and have file‑system access to the log file that contains the "supportsave" data. Thus the risk is limited to environments where log files are exposed to privileged or compromised users, but the impact of credential leakage is significant.

Generated by OpenCVE AI on October 8, 2026 at 06:21 UTC.

Remediation

Vendor Solution

Security update provided in Brocade SANnav 2.4.0b, 3.0.0 and 3.0.1


OpenCVE Recommended Actions

  • Update Brocade SANnav to version 2.4.0b, 3.0.0, or 3.0.1 to remove the log‑printing issue
  • Configure file‑system permissions so that only authorized system administrators can read SANnav log files
  • Audit and monitor log files for unauthorized access or manipulation
  • Ensure that credentials are rotated regularly to limit exposure in case of accidental disclosure

Generated by OpenCVE AI on October 8, 2026 at 06:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 06:45:00 +0000

Type Values Removed Values Added
Title Information Disclosure of Authentication Tokens via Log Files in Brocade SANnav

Thu, 08 Oct 2026 05:45:00 +0000

Type Values Removed Values Added
Description A vulnerability in Brocade SANnav before 2.4.0b and 3.0.0 prints encoded passwords and  authentication tokens in log files. The vulnerability could allow an authenticated attacker with access to the log file including the SANnav supportsave to access the passwords.
Weaknesses CWE-922
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published:

Updated: 2026-10-08T05:18:55.977Z

Reserved: 2026-03-27T16:45:32.682Z

Link: CVE-2026-5047

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T06:16:42.740

Modified: 2026-10-08T06:16:42.740

Link: CVE-2026-5047

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T06:30:17Z

Weaknesses
  • CWE-922

    Insecure Storage of Sensitive Information