Description
Improper handling of sensitive data during IPsec policy creation and modification in Brocade SANnav versions before 3.0.1a results in pre-shared keys being recorded in application logs. Individuals with read access to system log files or support bundles can view these credentials, leading to the potential exposure of keys used to secure network tunnels.
Published: 2026-09-24
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Exposure of IPsec pre‑shared keys through application logs
Action: Apply patch
AI Analysis

Impact

Brocade SANnav versions prior to 3.0.1a write pre‑shared keys to system logs during IPsec policy creation and modification. An attacker with read access to these logs can retrieve the keys, compromising the confidentiality of network tunnels. This flaw is a clear example of the improper handling of sensitive information in logs (CWE‑532).

Affected Systems

Brocade SANnav, any release earlier than version 3.0.1a. The vulnerability applies to the IPsec policy configuration functionality of that product, regardless of deployment scale.

Risk and Exploitability

The CVSS score of 8.5 indicates a high severity. Although the EPSS score is currently unavailable, the lack of an EPSS rating does not diminish the potential impact. The vulnerability is exploitable by any user with read access to system logs or support bundle files, meaning that local or privileged users could capture sensitive IPsec credentials. The flaw does not require network access or advanced attacker techniques, so its exploitation probability is high for systems where log access is not strictly controlled. The vulnerability is not listed in the CISA KEV catalog, but the exposure of encryption material makes it a serious threat.

Generated by OpenCVE AI on September 25, 2026 at 04:54 UTC.

Remediation

Vendor Solution

Security update provided in Brocade SANnav 3.0.1a


OpenCVE Recommended Actions

  • Update Brocade SANnav to version 3.0.1a or later, which removes the logging of pre‑shared keys.
  • Restrict read access to system log files and support bundles to privileged administrators only, enforcing a least‑privilege policy.
  • Implement strict key rotation and secure logging practices to prevent future accidental exposure of sensitive credential material.

Generated by OpenCVE AI on September 25, 2026 at 04:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Brocade
Brocade sannav
Vendors & Products Brocade
Brocade sannav

Thu, 24 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 24 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Description Improper handling of sensitive data during IPsec policy creation and modification in Brocade SANnav versions before 3.0.1a results in pre-shared keys being recorded in application logs. Individuals with read access to system log files or support bundles can view these credentials, leading to the potential exposure of keys used to secure network tunnels.
Title Improper handling of sensitive data during IPsec policy creation and modification in Brocade SANnav before 3.0.1.a
Weaknesses CWE-532
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published:

Updated: 2026-09-24T19:25:35.120Z

Reserved: 2026-08-28T19:39:58.088Z

Link: CVE-2026-82372

cve-icon Vulnrichment

Updated: 2026-09-24T19:25:29.351Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-24T20:17:32.353

Modified: 2026-09-25T13:16:34.693

Link: CVE-2026-82372

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T07:30:16Z

Weaknesses
  • CWE-532

    Insertion of Sensitive Information into Log File