PT-2026-98274 · Brocade · Sannav
CVE-2026-14443
·
Published
2026-09-24
·
Updated
2026-09-25
CVSS v4.0
8.4
High
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Brocade SANnav versions prior to 3.0.1a
Description
Incomplete log sanitization during bulk IPsec policy collection allows extension switch pre-shared keys to be written to system logs. Users with read access to container logs or support archives can obtain these keys, which may lead to the compromise of encrypted network tunnels.
Recommendations
Update Brocade SANnav to version 3.0.1a or later.
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sannav