Logging Vulnerability in Brocade SANnav Affects Admin Credentials
CVE-2025-12772

8.5HIGH

Key Information:

Vendor

Brocade

Status
Vendor
CVE Published:
2 February 2026

What is CVE-2025-12772?

A vulnerability in Brocade SANnav versions prior to 2.4.0b enables logging of sensitive admin credentials in clear text. This occurs when an Out of Memory (OOM) condition leads to the generation of heap dump files that inadvertently include the Brocade Fabric OS Switch admin password. If a remote authenticated attacker with sufficient privileges gains access to the SANnav logs or the support save files, they could compromise the admin password, leading to potential unauthorized management of the Brocade switch.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

SANnav before 2.4.0b

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.