PT-2026-98318 · Broadcom · Sannav
CVE-2026-85417
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v4.0
6.4
Medium
| Vector | AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
SANnav (affected versions not specified)
Description
Incomplete property masking in the logging subsystem allows SNMP authentication and privacy passwords to be recorded in application logs under specific configuration conditions. Users with read access to system logs or support bundles can retrieve these credentials, potentially granting unauthorized read or management access to monitored switch environments.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sannav