Brocade SANnav before SANnav 2.4.0a logs passwords and pbe keys in the Brocade SANnav server audit logs after installation and under specific conditions. These audit logs are the local server VM’s audit logs and are not controlled by SANnav. These logs are only visible to the server admin of the host server and are not visible to the SANnav admin or any SANnav user.
History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00013}

epss

{'score': 0.00017}


Fri, 11 Jul 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00013}


Thu, 10 Jul 2025 21:15:00 +0000

Type Values Removed Values Added
Description Brocade SANnav before SANnav 2.4.0a logs passwords and pbe keys in the Brocade SANnav server audit logs after installation and under specific conditions. These audit logs are the local server VM’s audit logs and are not controlled by SANnav. These logs are only visible to the server admin of the host server and are not visible to the SANnav admin or any SANnav user.
Title Cleartext storage of sensitive information in Brocade SANnav server audit logs.
Weaknesses CWE-497
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published: 2025-07-10T21:07:02.812Z

Updated: 2025-07-11T16:57:31.743Z

Reserved: 2025-06-20T02:28:16.267Z

Link: CVE-2025-6390

cve-icon Vulnrichment

Updated: 2025-07-11T16:56:00.494Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-10T21:15:29.530

Modified: 2025-07-15T13:14:49.980

Link: CVE-2025-6390

cve-icon Redhat

No data.