Brocade SANnav 发现服务日志文件中敏感认证数据的明文暴露,使得具有文件读取权限的个体能够获取管理交换机凭证和活跃会话令牌。能够访问系统日志或支持包的攻击者可以利用这些暴露的认证信息,破坏被管理的网络基础设施,并访问活跃的应用程序会话。此漏洞影响 Brocade SANnav 3.0.1a 之前的所有版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82372 | 8.5 HIGH | Improper handling of sensitive data during IPsec policy creation and modification in Broca |
| CVE-2026-14443 | 8.4 HIGH | Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav before 3 |
| CVE-2026-14441 | 6.9 MEDIUM | Logic flaw in SANnav Java cache key handling object comparison handling |
| CVE-2026-14442 | 6.9 MEDIUM | Information exposure vulnerability in the job scheduling component of SANnav before 3.0.1a |
No comments yet