CVE-2026-85417

Summary

Incomplete property masking in the SANnav logging subsystem permits SNMP authentication and privacy passwords to be recorded in application logs under specific configuration conditions. Individuals with read access to system logs or support bundles can retrieve these credentials, leading to unauthorized read or management access to monitored switch environments

Affected Software

VendorProductVersion RangeStatus
BrocadeSANnavbefore 3.0.1aaffected

Weaknesses

  • CWE-532: CWE-532: Insertion of Sensitive Information into Log File

References