Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-82371— Plaintext exposure of sensitive authentication data in SANnav discovery service log files

Quick assessment

Affected
Brocade SANnav
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Brocade SANnav 发现服务日志文件中敏感认证数据的明文暴露,使得具有文件读取权限的个体能够获取管理交换机凭证和活跃会话令牌。能够访问系统日志或支持包的攻击者可以利用这些暴露的认证信息,破坏被管理的网络基础设施,并访问活跃的应用程序会话。此漏洞影响 Brocade SANnav 3.0.1a 之前的所有版本。

CVSS 8.5 · High EPSS 0.12% · P2
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-82371

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Plaintext exposure of sensitive authentication data in SANnav discovery service log files
Source: CVE Program / CVE List V5
Vulnerability Description
Plaintext exposure of sensitive authentication data in Brocade SANnav discovery service log files enables individuals with file read access to retrieve administrative switch credentials and active session tokens. An attacker with access to system logs or support bundles can leverage exposed authentication details to compromise managed network infrastructure and access active application sessions. This vulnerability affects Brocade SANnav versions before 3.0.1a.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
通过日志文件的信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Brocade SANnav before 3.0.1a. -

II. Public POCs for CVE-2026-82371

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-82371

请登录查看更多情报信息。

Other References for CVE-2026-82371 (1)

Same Patch Batch · Brocade · 2026-09-24 · 5 CVEs total

CVE-2026-82372 8.5 HIGH Improper handling of sensitive data during IPsec policy creation and modification in Broca
CVE-2026-14443 8.4 HIGH Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav before 3
CVE-2026-14441 6.9 MEDIUM Logic flaw in SANnav Java cache key handling object comparison handling
CVE-2026-14442 6.9 MEDIUM Information exposure vulnerability in the job scheduling component of SANnav before 3.0.1a

IV. Related Vulnerabilities

V. Comments for CVE-2026-82371

No comments yet


Leave a comment