Improper Data Handling in Brocade SANnav Network Management
CVE-2026-82372

8.5HIGH

Key Information:

Vendor

Brocade

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-82372?

In Brocade SANnav versions prior to 3.0.1a, a vulnerability exists due to the improper handling of sensitive data during the creation and modification of IPsec policies. This flaw allows pre-shared keys to be recorded in application logs. Individuals who have read access to system log files or support bundles can potentially view these credentials, which may compromise the security of network tunnels. Proper precautions should be taken to secure log files and restrict access to mitigate associated risks.

Affected Version(s)

SANnav before 3.0.1

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.