CVE-2026-85417: Brocade Sannav
Medium severity, CVSS 6.4. EPSS: 0.2% chance of exploitation in the next 30 days.
Incomplete property masking in the SANnav logging subsystem permits SNMP authentication and privacy passwords to be recorded in application logs under specific configuration conditions. Individuals with read access to system logs or support bundles can retrieve these credentials, leading to unauthorized read or management access to monitored switch environments
Affected products
- Brocade Sannav: before 3.1.0a (fixed in 3.1.0a)
Published 2026-09-25. Last modified 2026-09-29.