PT-2026-98295 · Broadcom · Sannav
CVE-2026-14442
·
Published
2026-09-24
·
Updated
2026-09-25
CVSS v4.0
6.9
Medium
| Vector | AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
SANnav (affected versions not specified)
Description
An information exposure issue exists in the job scheduling component. When scheduled support save jobs or related operational tasks are executed, sensitive parameters such as external server passwords and archive protection keys are written to application logs in plain text without proper masking. A local or authenticated user with access to application logs or support bundles can view these cleartext credentials, which may lead to unauthorized access to protected archives or remote backup targets.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sannav