CVE-2019-16205: Broadcom Brocade Sannav

High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.

A vulnerability, in Brocade SANnav versions before v2.0, could allow remote attackers to brute-force a valid session ID. The vulnerability is due to an insufficiently random session ID for several post-authentication actions in the SANnav portal.

Affected products

  • Broadcom Brocade Sannav: before 2.0 (fixed in 2.0)

Published 2019-11-08. Last modified 2026-06-17.