CVE-2026-5047: high-severity vulnerability in Brocade SANnav
Published
18Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.2
exploitation probability
—
observed exploitation
nono source reports it
A vulnerability in Brocade SANnav before 2.4.0b and 3.0.0 prints encoded passwords and authentication tokens in log files. The vulnerability could allow an authenticated attacker with access to the log file including the SANnav supportsave to access the passwords.
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Affected products
Brocade · Brocade SANnavRelated CVEs — Brocade SANnav
In the same product, most dangerous first.
CVE-2024-2859MEDIUMBy default, SANnav OVA is shipped with root user login enabled (CVE-2024-2859)EPSS 0.8%CVE-2024-29961HIGHsupply-chain attack riskEPSS 0.8%CVE-2024-29966HIGHhard-coded credentials in the documentation that appear as the appliance root passwordEPSS 0.7%CVE-2024-4173HIGHSANnav versions exposes Kafka in the wan interface.EPSS 0.6%CVE-2024-29964MEDIUMBrocade SANnav versions before v2.3.0a do not correctly set permissions on files, including docker filesEPSS 0.5%CVE-2024-4159MEDIUMProtection mechanismsEPSS 0.5%