在 Brocade SANnav 3.0.1a 之前的版本中,在创建和修改 IPsec 策略时对敏感数据的处理不当,导致预共享密钥被记录到应用程序日志中。拥有系统日志文件或支持包读取权限的人员可以查看这些凭据,从而导致用于保护网络隧道的密钥存在泄露风险。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82371 | 8.5 HIGH | Plaintext exposure of sensitive authentication data in SANnav discovery service log files |
| CVE-2026-14443 | 8.4 HIGH | Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav before 3 |
| CVE-2026-14441 | 6.9 MEDIUM | Logic flaw in SANnav Java cache key handling object comparison handling |
| CVE-2026-14442 | 6.9 MEDIUM | Information exposure vulnerability in the job scheduling component of SANnav before 3.0.1a |
No comments yet