CVE-2025-12680

Brocade SANnav before Brocade SANnav 2.4.0b logs database passwords in clear text in the standby SANnav server, after disaster recovery failover. The vulnerability could allow a remote authenticated attacker with admin privilege able to access the SANnav logs or the supportsave to read the database password.
Configurations

Configuration 1 (hide)

cpe:2.3:a:broadcom:sannav:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-02-02 23:15

Updated : 2026-03-03 01:02


NVD link : CVE-2025-12680

Mitre link : CVE-2025-12680

CVE.ORG link : CVE-2025-12680


JSON object : View

Products Affected

broadcom

  • sannav
CWE
CWE-256

Plaintext Storage of a Password

CWE-312

Cleartext Storage of Sensitive Information