PT-2026-97506 · Brocade · Sannav
CVE-2026-82368
·
Published
2026-09-23
·
Updated
2026-09-23
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Brocade SANnav versions prior to 3.0.1a
Description
Insecure access controls on internal service ports allow local, non-administrative host users to communicate directly with backend management services. A local attacker can use this access to send commands to connected Fabric OS switches using the security context of the SANnav management user.
Recommendations
Update Brocade SANnav to version 3.0.1a or later.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sannav