Incomplete property masking in the SANnav logging subsystem permits SNMP authentication and privacy passwords to be recorded in application logs under specific configuration conditions. Individuals with read access to system logs or support bundles can retrieve these credentials, leading to unauthorized read or management access to monitored switch environments
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
Security update provided in Brocade SANnav 3.0.1a
Workaround
No workaround given by the vendor.
References
History
Fri, 25 Sep 2026 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incomplete property masking in the SANnav logging subsystem permits SNMP authentication and privacy passwords to be recorded in application logs under specific configuration conditions. Individuals with read access to system logs or support bundles can retrieve these credentials, leading to unauthorized read or management access to monitored switch environments | |
| Title | Incomplete property masking in the SANnav logging subsystem | |
| Weaknesses | CWE-532 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: brocade
Published:
Updated: 2026-09-25T00:03:17.324Z
Reserved: 2026-09-03T19:19:32.290Z
Link: CVE-2026-85417
No data.
Status : Received
Published: 2026-09-25T01:16:48.580
Modified: 2026-09-25T01:16:48.580
Link: CVE-2026-85417
No data.
OpenCVE Enrichment
No data.
Weaknesses