Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-85417— Incomplete property masking in the SANnav logging subsystem

Quick assessment

Affected
Brocade SANnav
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

SANnav 日志子系统存在属性掩码不完整的问题,导致在特定配置条件下,SNMP 认证密码和隐私密码会被记录在应用程序日志中。拥有系统日志或支持包读取权限的人员可以获取这些凭据,从而获得对受管交换机环境的未授权读取或管理访问权限。

CVSS 6.4 · Medium EPSS 0.19% · P8
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-85417

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Incomplete property masking in the SANnav logging subsystem
Source: CVE Program / CVE List V5
Vulnerability Description
Incomplete property masking in the SANnav logging subsystem permits SNMP authentication and privacy passwords to be recorded in application logs under specific configuration conditions. Individuals with read access to system logs or support bundles can retrieve these credentials, leading to unauthorized read or management access to monitored switch environments
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H
Source: CVE Program / CVE List V5
Vulnerability Type
通过日志文件的信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Brocade SANnav before 3.0.1a -

II. Public POCs for CVE-2026-85417

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-85417

请登录查看更多情报信息。

Other References for CVE-2026-85417 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-85417

No comments yet


Leave a comment