CVE-2025-12680

MEDIUM

Brocade SANnav <2.4.0b - Info Disclosure

Title source: llm
STIX 2.1

Description

Brocade SANnav before Brocade SANnav 2.4.0b logs database passwords in clear text in the standby SANnav server, after disaster recovery failover. The vulnerability could allow a remote authenticated attacker with admin privilege able to access the SANnav logs or the supportsave to read the database password.

Scores

CVSS v3 4.9
EPSS 0.0001
EPSS Percentile 1.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-256 CWE-312
Status published
Products (1)
broadcom/sannav < 2.4.0b
Published Feb 02, 2026
Tracked Since Feb 18, 2026