CVE-2025-12680: Brocade SANnav DataBase plaintext password is logged in failover logs (CVE-2025-12680)
Brocade SANnav before Brocade SANnav 2.4.0b logs database passwords in clear text in the standby SANnav server, after disaster recovery failover. The vulnerability could allow a remote authenticated attacker with admin privilege able to access the SANnav logs or the supportsave to read the database password.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12680?
CVE-2025-12680 is considered a high-severity vulnerability due to the exposure of plaintext database passwords.
How do I fix CVE-2025-12680?
To fix CVE-2025-12680, upgrade Brocade SANnav to version 2.4.0b or later, which addresses this logging issue.
Who is affected by CVE-2025-12680?
CVE-2025-12680 affects users of Brocade SANnav versions prior to 2.4.0b.
What could happen if CVE-2025-12680 is exploited?
If exploited, CVE-2025-12680 could allow an authenticated remote attacker to gain access to sensitive database credentials in clear text.
When was CVE-2025-12680 disclosed?
CVE-2025-12680 was disclosed in 2025, highlighting a vulnerability in the logging practices of Brocade SANnav.