CVE-2024-29966: Broadcom Brocade Sannav

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Brocade SANnav OVA before v2.3.1 and v2.3.0a contain hard-coded credentials in the documentation that appear as the appliance's root password. The vulnerability could allow an unauthenticated attacker full access to the Brocade SANnav appliance.

Affected products

  • Broadcom Brocade Sannav: before 2.3.0a (fixed in 2.3.0a)

Published 2024-04-19. Last modified 2026-06-17.