Description
Incomplete property masking in the SANnav logging subsystem permits SNMP authentication and privacy passwords to be recorded in application logs under specific configuration conditions. Individuals with read access to system logs or support bundles can retrieve these credentials, leading to unauthorized read or management access to monitored switch environments
Published: 2026-09-25
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Credential exposure from SNMP authentication and privacy passwords logged in unmasked form
Action: Immediate Patch
AI Analysis

Impact

Brocade SANnav’s logging subsystem does not fully mask SNMP credentials, resulting in authentication and privacy passwords being written to application logs under certain configuration settings. An adversary who can read the logs or obtain a support bundle can extract these credentials, gaining unauthorized management access to monitored switch environments. The weakness is a typical information disclosure vulnerability (CWE‑532).

Affected Systems

Systems running Brocade SANnav with the affected logging configuration. The security update addressing this flaw is available in Brocade SANnav 3.0.1a; earlier releases are potentially vulnerable if the logging settings are enabled to record SNMP credentials.

Risk and Exploitability

The CVSS score of 6.4 places the issue in the moderate severity range. No EPSS data is available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited publicly known exploitation. However, the vulnerability can be leveraged by anyone who gains local read access to the system logs or can procure a support bundle. Attackers might obtain the needed credentials by reading log files, escalating privileges with the recovered SNMP credentials, or by using the credentials to authenticate to the monitored switches. The likely attack vector is local or privileged access to the SANnav environment, and once credentials are exposed, remote authenticated access to the switches becomes possible.

Generated by OpenCVE AI on September 25, 2026 at 09:47 UTC.

Remediation

Vendor Solution

Security update provided in Brocade SANnav 3.0.1a


OpenCVE Recommended Actions

  • Apply the Brocade SANnav 3.0.1a security update, which removes the logging flaw.
  • Reconfigure the SANnav logging subsystem to mask SNMP authentication and privacy passwords if the update cannot be applied immediately.
  • Restrict log file access to only authorized system administrators and limit support bundle generation to trusted personnel.

Generated by OpenCVE AI on September 25, 2026 at 09:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Brocade
Brocade sannav
Vendors & Products Brocade
Brocade sannav

Fri, 25 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Incomplete property masking in the SANnav logging subsystem permits SNMP authentication and privacy passwords to be recorded in application logs under specific configuration conditions. Individuals with read access to system logs or support bundles can retrieve these credentials, leading to unauthorized read or management access to monitored switch environments
Title Incomplete property masking in the SANnav logging subsystem
Weaknesses CWE-532
References
Metrics cvssV4_0

{'score': 6.4, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published:

Updated: 2026-09-25T15:51:14.487Z

Reserved: 2026-09-03T19:19:32.290Z

Link: CVE-2026-85417

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-25T01:16:48.580

Modified: 2026-09-25T16:17:28.907

Link: CVE-2026-85417

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T10:00:16Z

Weaknesses
  • CWE-532

    Insertion of Sensitive Information into Log File