Impact
A flaw in Brocade SANnav versions prior to 2.4.0b, 3.0.0, and 3.0.1 causes the software to write encoded passwords and authentication tokens to log files. The flaw is associated with CWE-922 and allows the compromise of credential secrecy. An attacker who can read the log files can recover credentials that are intended to remain confidential.
Affected Systems
Brocade SANnav products affected include all releases before 2.4.0b and before 3.0.0. Users should verify whether they are running these unpatched versions.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.2, indicating high severity. EPSS data is unavailable, and the vulnerability is not listed in CISA KEV. Exploitation requires that the attacker be authenticated to the system and have file‑system access to the log file that contains the "supportsave" data. Thus the risk is limited to environments where log files are exposed to privileged or compromised users, but the impact of credential leakage is significant.
OpenCVE Enrichment