CVE-2020-15377: Broadcom Sannav

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

Webtools in Brocade SANnav before version 2.1.1 allows unauthenticated users to make requests to arbitrary hosts due to a misconfiguration; this is commonly referred to as Server-Side Request Forgery (SSRF).

Affected products

  • Broadcom Sannav: before 2.1.1 (fixed in 2.1.1)

Published 2021-06-09. Last modified 2026-06-17.