Impact
Brocade SANnav versions prior to 3.0.1a write pre‑shared keys to system logs during IPsec policy creation and modification. An attacker with read access to these logs can retrieve the keys, compromising the confidentiality of network tunnels. This flaw is a clear example of the improper handling of sensitive information in logs (CWE‑532).
Affected Systems
Brocade SANnav, any release earlier than version 3.0.1a. The vulnerability applies to the IPsec policy configuration functionality of that product, regardless of deployment scale.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity. Although the EPSS score is currently unavailable, the lack of an EPSS rating does not diminish the potential impact. The vulnerability is exploitable by any user with read access to system logs or support bundle files, meaning that local or privileged users could capture sensitive IPsec credentials. The flaw does not require network access or advanced attacker techniques, so its exploitation probability is high for systems where log access is not strictly controlled. The vulnerability is not listed in the CISA KEV catalog, but the exposure of encryption material makes it a serious threat.
OpenCVE Enrichment