CVE-2026-85417 PUBLISHED

Incomplete property masking in the SANnav logging subsystem

Assigner: brocade
Reserved: 03.09.2026 Published: 25.09.2026 Updated: 25.09.2026

Incomplete property masking in the SANnav logging subsystem permits SNMP authentication and privacy passwords to be recorded in application logs under specific configuration conditions. Individuals with read access to system logs or support bundles can retrieve these credentials, leading to unauthorized read or management access to monitored switch environments

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H
CVSS Score: 6.4

Product Status

Vendor Brocade
Product SANnav
Versions Default: affected
  • Version before 3.0.1a is affected

Solutions

Security update provided in Brocade SANnav 3.0.1a

References

Problem Types

  • CWE-532: Insertion of Sensitive Information into Log File CWE

Impacts

  • CAPEC-116: Excavation