PT-2026-107842 · Brocade · Sannav+1
CVE-2026-5769
·
Published
2026-10-08
·
Updated
2026-10-08
CVSS v4.0
5.6
Medium
| Vector | AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Brocade SANnav versions prior to 3.0.1
Description
An issue exists where the Brocade Fabric OS switch admin password may be captured in plaintext within a memory swap file on the server hosting the Brocade SANnav Virtual Machine. This occurs when the server encounters an Out Of Memory (OOM) condition, which is a state where the system has exhausted its available RAM and must move data to the disk. An authenticated admin user with access to the host server could potentially view this swap file to retrieve the password.
Recommendations
Update Brocade SANnav to version 3.0.1 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fabric Os
Sannav