Plaintext exposure of sensitive authentication data in Brocade SANnav discovery service log files enables individuals with file read access to retrieve administrative switch credentials and active session tokens. An attacker with access to system logs or support bundles can leverage exposed authentication details to compromise managed network infrastructure and access active application sessions. This vulnerability affects Brocade SANnav versions before 3.0.1a.
Advisories

No advisories yet.

Fixes

Solution

Security update provided in Brocade SANnav 3.0.1a


Workaround

No workaround given by the vendor.

History

Thu, 24 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 24 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description Plaintext exposure of sensitive authentication data in Brocade SANnav discovery service log files enables individuals with file read access to retrieve administrative switch credentials and active session tokens. An attacker with access to system logs or support bundles can leverage exposed authentication details to compromise managed network infrastructure and access active application sessions. This vulnerability affects Brocade SANnav versions before 3.0.1a.
Title Plaintext exposure of sensitive authentication data in SANnav discovery service log files
Weaknesses CWE-532
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published:

Updated: 2026-09-24T20:29:43.184Z

Reserved: 2026-08-28T19:39:58.088Z

Link: CVE-2026-82371

cve-icon Vulnrichment

Updated: 2026-09-24T18:37:42.711Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-24T19:17:18.047

Modified: 2026-09-24T20:17:32.240

Link: CVE-2026-82371

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses