Home/Product/broadcom brocade sannav
Product

broadcom brocade sannav

55 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-6392
< 2.4.0a
Brocade SANnav before Brocade SANnav 2.4.0a could log database passwords in clear text in audit logs when the daily data dump coll
4.4MEDIUM
CVE-2025-6390
< 2.4.0a
Brocade SANnav before SANnav 2.4.0a logs passwords and pbe keys in the Brocade SANnav server audit logs after installation and und
4.4MEDIUM
CVE-2025-4662
< 2.4.0a
Brocade SANnav before SANnav 2.4.0a logs plaintext passphrases in the Brocade SANnav host server audit logs while executing OpenSS
4.4MEDIUM
CVE-2024-4282
< 2.3.1b
Brocade SANnav OVA before SANnav 2.3.1b enables SHA1 deprecated setting for SSH for port 22.
9.8CRITICAL
CVE-2024-10405
< 2.3.1b
Brocade SANnav before SANnav 2.3.1b enables weak TLS ciphers on ports 443 and 18082. In case of a successful exploit, an attacke
5.3MEDIUM
CVE-2024-2240
< 2.3.1b
Docker daemon in Brocade SANnav before SANnav 2.3.1b runs without auditing. The vulnerability could allow a remote authenticated a
7.2HIGH
CVE-2025-1053
< 2.3.1b
Under certain error conditions at time of SANnav installation or upgrade, the encryption key can be written into and obtained from
4.9MEDIUM
CVE-2024-10404
< 2.3.1b
CalInvocationHandler in Brocade SANnav before 2.3.1b logs sensitive information in clear text. The vulnerability could allow an
5.5MEDIUM
CVE-2022-43937
< 2.2.2a
Possible information exposure through log file vulnerability where sensitive fields are recorded in the debug-enabled logs when de
5.7MEDIUM
CVE-2022-43936
< 2.2.2
Brocade SANnav versions before 2.2.2 log Brocade Fabric OS switch passwords when debugging is enabled.
6.8MEDIUM
CVE-2022-43935
< 2.2.2
An information exposure through log file vulnerability exists in Brocade SANnav before Brocade SANnav 2.2.2, where Brocade Fabric
5.3MEDIUM
CVE-2022-43934
< 2.2.2
Brocade SANnav before Brocade SANnav 2.2.2 supports key exchange algorithms, which are considered weak on ports 24, 6514, 18023, 1
6.5MEDIUM
CVE-2022-43933
< 2.2.2
An information exposure through log file vulnerability exists in Brocade SANnav before Brocade SANnav 2.2.2, where configuration s
4.4MEDIUM
CVE-2024-3596
all versions
RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Acc
9.0CRITICAL
CVE-2024-2860
< 2.3.0a
The PostgreSQL implementation in Brocade SANnav versions before 2.3.0a is vulnerable to an incorrect local authentication flaw. An
7.8HIGH
CVE-2024-2859
< 2.3.0
By default, SANnav OVA is shipped with root user login enabled. While protected by a password, access to root could expose SANnav
6.8MEDIUM
CVE-2024-4173
< 2.2.0
A vulnerability in Brocade SANnav exposes Kafka in the wan interface. The vulnerability could allow an unauthenticated attacker t
7.6HIGH
CVE-2024-4161
< 2.3.0
In Brocade SANnav, before Brocade SANnav v2.3.0, syslog traffic received clear text. This could allow an unauthenticated, remote
8.6HIGH
CVE-2024-4159
< 2.3.0a
Brocade SANnav before v2.3.0a lacks protection mechanisms on port 2377/TCP and 7946/TCP, which could allow an unauthenticated atta
4.3MEDIUM
CVE-2024-29969
>= 2.2.2 and < 2.3.0a
When a Brocade SANnav installation is upgraded from Brocade SANnav v2.2.2 to Brocade SANnav 2.3.0, TLS/SSL weak message authentica
7.5HIGH
CVE-2024-29968
< 2.3.0a
An information disclosure vulnerability exists in Brocade SANnav before v2.3.1 and v2.3.0a when Brocade SANnav instances are confi
7.7HIGH
CVE-2024-29967
< 2.3.0a
In Brocade SANnav before Brocade SANnav v2.31 and v2.3.0a, it was observed that Docker instances inside the appliance have insecur
4.4MEDIUM
CVE-2024-29966
< 2.3.0a
Brocade SANnav OVA before v2.3.1 and v2.3.0a contain hard-coded credentials in the documentation that appear as the appliance's ro
7.5HIGH
CVE-2024-29965
< 2.3.0a
In Brocade SANnav before v2.3.1, and v2.3.0a, it is possible to back up the appliance from the web interface or the command line i
6.8MEDIUM
CVE-2024-29964
< 2.3.0a
Brocade SANnav versions before v2.3.0a do not correctly set permissions on files, including docker files. An unprivileged attacker
5.7MEDIUM
CVE-2024-29962
< 2.3.0a
Brocade SANnav OVA before v2.3.1 and v2.3.0a have an insecure file permission setting that makes files world-readable. This could
5.5MEDIUM
CVE-2024-29963
< 2.3.0a
Brocade SANnav OVA before v2.3.1, and v2.3.0a, contain hardcoded TLS keys used by Docker. Note: Brocade SANnav doesn't have access
1.9LOW
CVE-2024-29961
< 2.3.0a
A vulnerability affects Brocade SANnav before v2.3.1 and v2.3.0a. It allows a Brocade SANnav service to send ping commands in the
8.2HIGH
CVE-2024-29960
< 2.3.0a
In Brocade SANnav server before v2.3.1 and v2.3.0a, the SSH keys inside the OVA image are identical in the VM every time SANnav is
6.8MEDIUM
CVE-2024-29959
< 2.3.0a
A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints Brocade Fabric OS switch encrypted passwords in the Brocade SAN
8.6HIGH
CVE-2024-29958
< 2.3.0a
A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints the encryption key in the console when a privileged user execut
7.5HIGH
CVE-2024-29957
< 2.3.0a
When Brocade SANnav before v2.3.1 and v2.3.0a servers are configured in Disaster Recovery mode, the encryption key is stored in th
7.5HIGH
CVE-2024-29956
< 2.3.0a
A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints the Brocade SANnav password in clear text in supportsave logs w
6.5MEDIUM
CVE-2024-29955
< 2.3.0a
A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow a privileged user to print the SANnav encrypted key in Pos
5.0MEDIUM
CVE-2024-29952
< 2.3.0a
A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow an authenticated user to print the Auth, Priv, and SSL key
5.5MEDIUM
CVE-2024-29951
< 2.3.0a
Brocade SANnav before v2.3.1 and v2.3.0a uses the SHA-1 hash in internal SSH ports that are not open to remote connection.
5.7MEDIUM
CVE-2024-29950
< 2.3.0a
The class FileTransfer implemented in Brocade SANnav before v2.3.1, v2.3.0a, uses the ssh-rsa signature scheme, which has a SHA-1
7.5HIGH
CVE-2023-31925
< 2.2.2a
Brocade SANnav before v2.3.0 and v2.2.2a stores SNMPv3 Authentication passwords in plaintext. A privileged user could retrieve t
5.4MEDIUM
CVE-2023-31424
< 2.2.2a
Brocade SANnav Web interface before Brocade SANnav v2.3.0 and v2.2.2a allows remote unauthenticated users to bypass web authentic
8.1HIGH
CVE-2023-31423
< 2.2.2a
Possible information exposure through log file vulnerability where sensitive fields are recorded in the configuration log withou
5.7MEDIUM
CVE-2022-33187
< 2.2.1
Brocade SANnav before v2.2.1 logs usernames and encoded passwords in debug-enabled logs. The vulnerability could allow an attacke
5.5MEDIUM
CVE-2022-28161
< 2.2.0
An information exposure through log file vulnerability in Brocade SANNav versions before Brocade SANnav 2.2.0 could allow an authe
5.5MEDIUM
CVE-2022-23305
all versions
By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted a
9.8CRITICAL
CVE-2022-23302
all versions
JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the
8.8HIGH
CVE-2020-15387
< 2.1.1
The host SSH servers of Brocade Fabric OS before Brocade Fabric OS v7.4.2h, v8.2.1c, v8.2.2, v9.0.0, and Brocade SANnav before v2.
7.4HIGH
CVE-2020-15379
<= 2.1.0
Brocade SANnav before v.2.1.0a could allow remote attackers cause a denial-of-service condition due to a lack of proper validation
7.5HIGH
CVE-2020-15382
< 2.1.1
Brocade SANnav before version 2.1.1 uses a hard-coded administrator account with the weak password ‘passw0rd’ if a password is
7.2HIGH
CVE-2019-16212
< 2.1.0
A vulnerability in Brocade SANnav versions before v2.1.0 could allow a remote authenticated attacker to conduct an LDAP injection.
8.8HIGH
CVE-2019-16211
< 2.1.0
Brocade SANnav versions before v2.1.0, contain a Plaintext Password Storage vulnerability.
9.8CRITICAL
CVE-2019-16210
< 2.0
Brocade SANnav versions before v2.0, logs plain text database connection password while triggering support save.
5.5MEDIUM
CVE-2019-16209
< 2.0
A vulnerability, in The ReportsTrustManager class of Brocade SANnav versions before v2.0, could allow an attacker to perform a man
7.4HIGH
CVE-2019-16208
< 2.0
Password-based encryption (PBE) algorithm, of Brocade SANnav versions before v2.0, has a weakness in generating cryptographic keys
7.5HIGH
CVE-2019-16207
< 2.0
Brocade SANnav versions before v2.0 use a hard-coded password, which could allow local authenticated attackers to access a back-en
7.8HIGH
CVE-2019-16206
< 2.0
The authentication mechanism, in Brocade SANnav versions before v2.0, logs plaintext account credentials at the ‘trace’ and th
5.5MEDIUM
CVE-2019-16205
< 2.0
A vulnerability, in Brocade SANnav versions before v2.0, could allow remote attackers to brute-force a valid session ID. The vulne
8.8HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin