CVE-2024-2859: Broadcom Brocade Sannav

High severity, CVSS 7.2. EPSS: 0.8% chance of exploitation in the next 30 days.

By default, SANnav OVA is shipped with root user login enabled. While protected by a password, access to root could expose SANnav to a remote attacker should they gain access to the root account.

Affected products

  • Broadcom Brocade Sannav: before 2.3.0 (fixed in 2.3.0)

Published 2024-04-27. Last modified 2026-06-17.