Brocade SANnav
cpe:2.3:a:broadcom:brocade_sannav:*:*:*:*:*:*:*
- < 2.4.0b
A vulnerability exists in Brocade SANnav versions prior to 2.4.0b, where database passwords are logged in clear text on the standby SANnav server following a disaster recovery failover. This issue could enable a remote authenticated attacker with admin privileges to access SANnav logs or the supportsave feature to retrieve the database password.
Exploitation of this vulnerability could lead to unauthorized access to database passwords, potentially allowing for further exploitation of the SANnav server or its components.
Users can upgrade to Brocade SANnav versions 3.0 or 2.4.0b to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.