threat
engine
.sh
Back
·
··:··
Home
/
Product
/
broadcom brocade sannav
Product
broadcom brocade sannav
55 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2025-6392
< 2.4.0a
Brocade SANnav before Brocade SANnav 2.4.0a could log database passwords in clear text in audit logs when the daily data dump coll
4.4
MEDIUM
CVE-2025-6390
< 2.4.0a
Brocade SANnav before SANnav 2.4.0a logs passwords and pbe keys in the Brocade SANnav server audit logs after installation and und
4.4
MEDIUM
CVE-2025-4662
< 2.4.0a
Brocade SANnav before SANnav 2.4.0a logs plaintext passphrases in the Brocade SANnav host server audit logs while executing OpenSS
4.4
MEDIUM
CVE-2024-4282
< 2.3.1b
Brocade SANnav OVA before SANnav 2.3.1b enables SHA1 deprecated setting for SSH for port 22.
9.8
CRITICAL
CVE-2024-10405
< 2.3.1b
Brocade SANnav before SANnav 2.3.1b enables weak TLS ciphers on ports 443 and 18082. In case of a successful exploit, an attacke
5.3
MEDIUM
CVE-2024-2240
< 2.3.1b
Docker daemon in Brocade SANnav before SANnav 2.3.1b runs without auditing. The vulnerability could allow a remote authenticated a
7.2
HIGH
CVE-2025-1053
< 2.3.1b
Under certain error conditions at time of SANnav installation or upgrade, the encryption key can be written into and obtained from
4.9
MEDIUM
CVE-2024-10404
< 2.3.1b
CalInvocationHandler in Brocade SANnav before 2.3.1b logs sensitive information in clear text. The vulnerability could allow an
5.5
MEDIUM
CVE-2022-43937
< 2.2.2a
Possible information exposure through log file vulnerability where sensitive fields are recorded in the debug-enabled logs when de
5.7
MEDIUM
CVE-2022-43936
< 2.2.2
Brocade SANnav versions before 2.2.2 log Brocade Fabric OS switch passwords when debugging is enabled.
6.8
MEDIUM
CVE-2022-43935
< 2.2.2
An information exposure through log file vulnerability exists in Brocade SANnav before Brocade SANnav 2.2.2, where Brocade Fabric
5.3
MEDIUM
CVE-2022-43934
< 2.2.2
Brocade SANnav before Brocade SANnav 2.2.2 supports key exchange algorithms, which are considered weak on ports 24, 6514, 18023, 1
6.5
MEDIUM
CVE-2022-43933
< 2.2.2
An information exposure through log file vulnerability exists in Brocade SANnav before Brocade SANnav 2.2.2, where configuration s
4.4
MEDIUM
CVE-2024-3596
all versions
RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Acc
9.0
CRITICAL
CVE-2024-2860
< 2.3.0a
The PostgreSQL implementation in Brocade SANnav versions before 2.3.0a is vulnerable to an incorrect local authentication flaw. An
7.8
HIGH
CVE-2024-2859
< 2.3.0
By default, SANnav OVA is shipped with root user login enabled. While protected by a password, access to root could expose SANnav
6.8
MEDIUM
CVE-2024-4173
< 2.2.0
A vulnerability in Brocade SANnav exposes Kafka in the wan interface. The vulnerability could allow an unauthenticated attacker t
7.6
HIGH
CVE-2024-4161
< 2.3.0
In Brocade SANnav, before Brocade SANnav v2.3.0, syslog traffic received clear text. This could allow an unauthenticated, remote
8.6
HIGH
CVE-2024-4159
< 2.3.0a
Brocade SANnav before v2.3.0a lacks protection mechanisms on port 2377/TCP and 7946/TCP, which could allow an unauthenticated atta
4.3
MEDIUM
CVE-2024-29969
>= 2.2.2 and < 2.3.0a
When a Brocade SANnav installation is upgraded from Brocade SANnav v2.2.2 to Brocade SANnav 2.3.0, TLS/SSL weak message authentica
7.5
HIGH
CVE-2024-29968
< 2.3.0a
An information disclosure vulnerability exists in Brocade SANnav before v2.3.1 and v2.3.0a when Brocade SANnav instances are confi
7.7
HIGH
CVE-2024-29967
< 2.3.0a
In Brocade SANnav before Brocade SANnav v2.31 and v2.3.0a, it was observed that Docker instances inside the appliance have insecur
4.4
MEDIUM
CVE-2024-29966
< 2.3.0a
Brocade SANnav OVA before v2.3.1 and v2.3.0a contain hard-coded credentials in the documentation that appear as the appliance's ro
7.5
HIGH
CVE-2024-29965
< 2.3.0a
In Brocade SANnav before v2.3.1, and v2.3.0a, it is possible to back up the appliance from the web interface or the command line i
6.8
MEDIUM
CVE-2024-29964
< 2.3.0a
Brocade SANnav versions before v2.3.0a do not correctly set permissions on files, including docker files. An unprivileged attacker
5.7
MEDIUM
CVE-2024-29962
< 2.3.0a
Brocade SANnav OVA before v2.3.1 and v2.3.0a have an insecure file permission setting that makes files world-readable. This could
5.5
MEDIUM
CVE-2024-29963
< 2.3.0a
Brocade SANnav OVA before v2.3.1, and v2.3.0a, contain hardcoded TLS keys used by Docker. Note: Brocade SANnav doesn't have access
1.9
LOW
CVE-2024-29961
< 2.3.0a
A vulnerability affects Brocade SANnav before v2.3.1 and v2.3.0a. It allows a Brocade SANnav service to send ping commands in the
8.2
HIGH
CVE-2024-29960
< 2.3.0a
In Brocade SANnav server before v2.3.1 and v2.3.0a, the SSH keys inside the OVA image are identical in the VM every time SANnav is
6.8
MEDIUM
CVE-2024-29959
< 2.3.0a
A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints Brocade Fabric OS switch encrypted passwords in the Brocade SAN
8.6
HIGH
CVE-2024-29958
< 2.3.0a
A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints the encryption key in the console when a privileged user execut
7.5
HIGH
CVE-2024-29957
< 2.3.0a
When Brocade SANnav before v2.3.1 and v2.3.0a servers are configured in Disaster Recovery mode, the encryption key is stored in th
7.5
HIGH
CVE-2024-29956
< 2.3.0a
A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints the Brocade SANnav password in clear text in supportsave logs w
6.5
MEDIUM
CVE-2024-29955
< 2.3.0a
A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow a privileged user to print the SANnav encrypted key in Pos
5.0
MEDIUM
CVE-2024-29952
< 2.3.0a
A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow an authenticated user to print the Auth, Priv, and SSL key
5.5
MEDIUM
CVE-2024-29951
< 2.3.0a
Brocade SANnav before v2.3.1 and v2.3.0a uses the SHA-1 hash in internal SSH ports that are not open to remote connection.
5.7
MEDIUM
CVE-2024-29950
< 2.3.0a
The class FileTransfer implemented in Brocade SANnav before v2.3.1, v2.3.0a, uses the ssh-rsa signature scheme, which has a SHA-1
7.5
HIGH
CVE-2023-31925
< 2.2.2a
Brocade SANnav before v2.3.0 and v2.2.2a stores SNMPv3 Authentication passwords in plaintext. A privileged user could retrieve t
5.4
MEDIUM
CVE-2023-31424
< 2.2.2a
Brocade SANnav Web interface before Brocade SANnav v2.3.0 and v2.2.2a allows remote unauthenticated users to bypass web authentic
8.1
HIGH
CVE-2023-31423
< 2.2.2a
Possible information exposure through log file vulnerability where sensitive fields are recorded in the configuration log withou
5.7
MEDIUM
CVE-2022-33187
< 2.2.1
Brocade SANnav before v2.2.1 logs usernames and encoded passwords in debug-enabled logs. The vulnerability could allow an attacke
5.5
MEDIUM
CVE-2022-28161
< 2.2.0
An information exposure through log file vulnerability in Brocade SANNav versions before Brocade SANnav 2.2.0 could allow an authe
5.5
MEDIUM
CVE-2022-23305
all versions
By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted a
9.8
CRITICAL
CVE-2022-23302
all versions
JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the
8.8
HIGH
CVE-2020-15387
< 2.1.1
The host SSH servers of Brocade Fabric OS before Brocade Fabric OS v7.4.2h, v8.2.1c, v8.2.2, v9.0.0, and Brocade SANnav before v2.
7.4
HIGH
CVE-2020-15379
<= 2.1.0
Brocade SANnav before v.2.1.0a could allow remote attackers cause a denial-of-service condition due to a lack of proper validation
7.5
HIGH
CVE-2020-15382
< 2.1.1
Brocade SANnav before version 2.1.1 uses a hard-coded administrator account with the weak password ‘passw0rd’ if a password is
7.2
HIGH
CVE-2019-16212
< 2.1.0
A vulnerability in Brocade SANnav versions before v2.1.0 could allow a remote authenticated attacker to conduct an LDAP injection.
8.8
HIGH
CVE-2019-16211
< 2.1.0
Brocade SANnav versions before v2.1.0, contain a Plaintext Password Storage vulnerability.
9.8
CRITICAL
CVE-2019-16210
< 2.0
Brocade SANnav versions before v2.0, logs plain text database connection password while triggering support save.
5.5
MEDIUM
CVE-2019-16209
< 2.0
A vulnerability, in The ReportsTrustManager class of Brocade SANnav versions before v2.0, could allow an attacker to perform a man
7.4
HIGH
CVE-2019-16208
< 2.0
Password-based encryption (PBE) algorithm, of Brocade SANnav versions before v2.0, has a weakness in generating cryptographic keys
7.5
HIGH
CVE-2019-16207
< 2.0
Brocade SANnav versions before v2.0 use a hard-coded password, which could allow local authenticated attackers to access a back-en
7.8
HIGH
CVE-2019-16206
< 2.0
The authentication mechanism, in Brocade SANnav versions before v2.0, logs plaintext account credentials at the ‘trace’ and th
5.5
MEDIUM
CVE-2019-16205
< 2.0
A vulnerability, in Brocade SANnav versions before v2.0, could allow remote attackers to brute-force a valid session ID. The vulne
8.8
HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin