CVE-2026-85417: Incomplete property masking in the SANnav logging subsystem
Incomplete property masking in the SANnav logging subsystem permits SNMP authentication and privacy passwords to be recorded in application logs under specific configuration conditions. Individuals with read access to system logs or support bundles can retrieve these credentials, leading to unauthorized read or management access to monitored switch environments
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Brocade SANnavto a version that resolves this vulnerability.Fixed in 3.0.1a
Event History
Frequently Asked Questions
Who could obtain the exposed SNMP credentials?
Anyone with read access to SANnav application logs or support bundles may be able to retrieve SNMP authentication and privacy passwords when they have been recorded under the affected configuration conditions.
What access could leaked credentials enable?
The retrieved credentials could allow unauthorized read or management access to monitored switch environments.