Logging Vulnerability in Brocade SANnav Affects Admin Credentials
CVE-2025-12772
8.5HIGH
What is CVE-2025-12772?
A vulnerability in Brocade SANnav versions prior to 2.4.0b enables logging of sensitive admin credentials in clear text. This occurs when an Out of Memory (OOM) condition leads to the generation of heap dump files that inadvertently include the Brocade Fabric OS Switch admin password. If a remote authenticated attacker with sufficient privileges gains access to the SANnav logs or the support save files, they could compromise the admin password, leading to potential unauthorized management of the Brocade switch.
Affected Version(s)
SANnav before 2.4.0b