{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-5047", "assignerOrgId": "87b297d7-335e-4844-9551-11b97995a791", "state": "PUBLISHED", "assignerShortName": "brocade", "dateReserved": "2026-03-27T16:45:32.682Z", "datePublished": "2026-10-08T05:18:55.977Z", "dateUpdated": "2026-10-08T05:18:55.977Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "87b297d7-335e-4844-9551-11b97995a791", "shortName": "brocade", "dateUpdated": "2026-10-08T05:18:55.977Z" }, "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-922", "description": "CWE-922: Insecure Storage of Sensitive Information", "type": "CWE" } ] } ], "impacts": [ { "capecId": "CAPEC-37", "descriptions": [ { "lang": "en", "value": "CAPEC-37 Retrieve Embedded Sensitive Data" } ] } ], "affected": [ { "vendor": "Brocade", "product": "Brocade SANnav", "versions": [ { "status": "affected", "version": "0", "lessThan": "2.4.0b", "versionType": "Brocade SANnav" }, { "status": "affected", "version": "3.0.0", "versionType": "Brocade SANnav" } ], "defaultStatus": "unaffected" } ], "descriptions": [ { "lang": "en", "value": "A vulnerability in Brocade SANnav before 2.4.0b and 3.0.0 prints encoded passwords and  authentication tokens in log files. The vulnerability could allow an authenticated attacker with access to the log file including the SANnav supportsave to access the passwords.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "

A vulnerability in Brocade SANnav before 2.4.0b and 3.0.0 prints encoded passwords and  authentication tokens in log files. The vulnerability could allow an authenticated attacker with access to the log file including the SANnav supportsave to access the passwords.

" } ] } ], "references": [ { "url": "https://support.broadcom.com/external/content/SecurityAdvisories/0/37933" } ], "metrics": [ { "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ], "cvssV4_0": { "attackVector": "ADJACENT", "attackComplexity": "LOW", "attackRequirements": "NONE", "privilegesRequired": "NONE", "userInteraction": "PASSIVE", "vulnConfidentialityImpact": "HIGH", "subConfidentialityImpact": "HIGH", "vulnIntegrityImpact": "NONE", "subIntegrityImpact": "NONE", "vulnAvailabilityImpact": "NONE", "subAvailabilityImpact": "NONE", "exploitMaturity": "NOT_DEFINED", "Safety": "NOT_DEFINED", "Automatable": "NOT_DEFINED", "Recovery": "NOT_DEFINED", "valueDensity": "NOT_DEFINED", "vulnerabilityResponseEffort": "NOT_DEFINED", "providerUrgency": "NOT_DEFINED", "version": "4.0", "baseSeverity": "HIGH", "baseScore": 8.2, "vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N" } } ], "solutions": [ { "lang": "en", "value": "Security update provided in Brocade SANnav 2.4.0b, 3.0.0 and 3.0.1", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "
Security update provided in Brocade SANnav 2.4.0b, 3.0.0 and 3.0.1
" } ] } ], "source": { "discovery": "UNKNOWN" }, "x_generator": { "engine": "Vulnogram 1.0.5" } } } }