VendorsBroadcombrocade_sannavany version
Vulnerabilities

Broadcom Brocade any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

54CVEs
CVE-2022-23305
SQL injection in JDBC Appender in Apache Log4j V1
Published 2022-01-18 · Modified
9.8EPSS 0.665
CVE-2019-16211
Brocade SANnav versions before v2.1.0, contain a Plaintext Password Storage vulnerability.
Published 2020-09-25 · Modified
9.8EPSS 0.010
CVE-2023-31424
Web authentication and authorization bypass
Published 2023-08-31 · Modified
9.8EPSS 0.009
CVE-2024-29966
hard-coded credentials in the documentation that appear as the appliance root password
Published 2024-04-19 · Analyzed
9.8EPSS 0.007
CVE-2024-4173
SANnav versions exposes Kafka in the wan interface.
Published 2024-04-25 · Analyzed
9.8EPSS 0.006
CVE-2024-4282
Weak TLS Ciphers on Brocade SANnav OVA SSH port 22
Published 2025-02-14 · Analyzed
9.8EPSS 0.003
CVE-2024-3596
RADIUS Protocol under RFC2865 is vulnerable to forgery attacks.
Published 2024-07-09 · Modified
9.0EPSS 0.149
CVE-2022-23302
Deserialization of untrusted data in JMSSink in Apache Log4j 1.x
Published 2022-01-18 · Modified
8.8EPSS 0.636
CVE-2019-16212
A vulnerability in Brocade SANnav versions before v2.1.0 could allow a remote authenticated attacker to conduct an LDAP injection. The vulnerability could allow a remote attacker to bypass the authentication process.
Published 2020-09-25 · Modified
8.8EPSS 0.019
CVE-2019-16205
A vulnerability, in Brocade SANnav versions before v2.0, could allow remote attackers to brute-force a valid session ID. The vulnerability is due to an insufficiently random session ID for several post-authentication actions in the SANnav portal.
Published 2019-11-08 · Modified
8.8EPSS 0.013
CVE-2024-2240
Docker implementation in Brocade SANnav is missing Audit Rules.
Published 2025-02-14 · Analyzed
8.6EPSS 0.005
CVE-2024-29959
Brocade Fabric OS switch encrypted passwords in the Brocade SANnav Standby node's support save
Published 2024-04-19 · Analyzed
8.6EPSS 0.005
CVE-2024-4161
Syslog traffic sent in clear-text
Published 2024-04-25 · Analyzed
8.6EPSS 0.005
CVE-2025-1053
Brocade SANnav encryption key is logged in the debug logs
Published 2025-02-14 · Analyzed
8.6EPSS 0.002
CVE-2024-29961
supply-chain attack risk
Published 2024-04-19 · Analyzed
8.2EPSS 0.008
CVE-2019-16207
Brocade SANnav versions before v2.0 use a hard-coded password, which could allow local authenticated attackers to access a back-end database and gain privileges.
Published 2019-11-08 · Modified
7.8EPSS 0.003
CVE-2024-2860
The PostgreSQL implementation in Brocade SANnav versions before 2.3.0a is vulnerable to an incorrect local authentication flaw. An attacker accessing the VM where the Brocade SANnav is installed can gain access to sensitive data inside the PostgreSQL database.
Published 2024-05-08 · Analyzed
7.8EPSS 0.002
CVE-2024-29968
SQL Table names, column names, and SQL queries are collected in DR standby Supportsave
Published 2024-04-19 · Analyzed
7.7EPSS 0.005
CVE-2020-15379
Brocade SANnav before v.2.1.0a could allow remote attackers cause a denial-of-service condition due to a lack of proper validation, of the length of user-supplied data as name for custom field name.
Published 2021-06-09 · Modified
7.5EPSS 0.013
CVE-2022-43934
Weak Key-exchange algorithms
Published 2024-11-21 · Analyzed
7.5EPSS 0.005
CVE-2019-16208
Password-based encryption (PBE) algorithm, of Brocade SANnav versions before v2.0, has a weakness in generating cryptographic keys that may allow an attacker to decrypt passwords used with several services (Radius, TACAS, etc.).
Published 2019-11-08 · Modified
7.5EPSS 0.004
CVE-2024-29960
Identical SSH keys utilized inside the OVA image (CVE-2024-29960)
Published 2024-04-19 · Analyzed
7.5EPSS 0.003
CVE-2024-29950
Brocade SANnav before v2.3.1, v2.3.0a uses weak encryption
Published 2024-04-17 · Analyzed
7.5EPSS 0.003
CVE-2024-29957
Encryption key is stored in the DR log files
Published 2024-04-19 · Analyzed
7.5EPSS 0.003
CVE-2024-29969
TLS/SSL weak message authentication code ciphers are added by default for port 18082
Published 2024-04-19 · Analyzed
7.5EPSS 0.003
CVE-2024-29958
Encryption key in the console when a privileged user executes the script to replace the Brocade SANnav Management Portal standby node.
Published 2024-04-19 · Analyzed
7.5EPSS 0.003
CVE-2019-16209
A vulnerability, in The ReportsTrustManager class of Brocade SANnav versions before v2.0, could allow an attacker to perform a man-in-the-middle attack against Secure Sockets Layer(SSL)connections.
Published 2019-11-08 · Modified
7.4EPSS 0.007
CVE-2020-15387
The host SSH servers of Brocade Fabric OS before Brocade Fabric OS v7.4.2h, v8.2.1c, v8.2.2, v9.0.0, and Brocade SANnav before v2.1.1 utilize keys of less than 2048 bits, which may be vulnerable to man-in-the-middle attacks and/or insecure SSH communications.
Published 2021-06-09 · Modified
7.4EPSS 0.005
CVE-2020-15382
Brocade SANnav before version 2.1.1 uses a hard-coded administrator account with the weak password ‘passw0rd’ if a password is not provided for PostgreSQL at install-time.
Published 2021-06-09 · Modified
7.2EPSS 0.009
CVE-2024-2859
By default, SANnav OVA is shipped with root user login enabled (CVE-2024-2859)
Published 2024-04-27 · Analyzed
7.2EPSS 0.008
CVE-2024-10405
Weak TLS Ciphers on Brocade SANnav port 443 & 18082
Published 2025-02-14 · Analyzed
6.9EPSS 0.002
CVE-2022-43936
Brocade Fabric OS switch passwords when debugging is enabled
Published 2024-11-21 · Analyzed
6.8EPSS 0.008
CVE-2024-29965
Insecure backup
Published 2024-04-19 · Analyzed
6.8EPSS 0.004
CVE-2025-6392
Daily Data Dump Collector logs database password in cleartext when running docker exec commands (CVE-2025-6392)
Published 2025-07-10 · Analyzed
6.7EPSS 0.001
CVE-2024-29964
Brocade SANnav versions before v2.3.0a do not correctly set permissions on files, including docker files
Published 2024-04-19 · Analyzed
6.5EPSS 0.005
CVE-2024-29956
cleartext password in supportsave logs when a user schedules a switch Supportsave from Brocade SANnav
Published 2024-04-18 · Analyzed
6.5EPSS 0.003
CVE-2023-31925
Storage of clear text password in Brocade SANnav
Published 2023-08-31 · Modified
6.5EPSS 0.002
CVE-2024-29967
In Brocade SANnav before v2.31 and v2.3.0a, it was observed that Docker instances inside the appliance have insecure mount points
Published 2024-04-19 · Analyzed
6.0EPSS 0.002
CVE-2022-43937
Brocade SANnav Information Disclosure Vulnerability
Published 2024-11-21 · Analyzed
5.7EPSS 0.005
CVE-2023-31423
Possible information exposure through log file vulnerability
Published 2023-08-31 · Modified
5.7EPSS 0.002
1 / 2Next →