CVE-2026-14443
8.4Brocade · SANnav
Brocade SANnav fails to sanitize logs during IPsec policy collection, causing sensitive pre-shared keys to be written to system logs where they are accessible to unauthorized users.
Executive summary
A vulnerability in Brocade SANnav versions before 3.0.1a allows authenticated users with log access to retrieve sensitive pre-shared keys, potentially compromising encrypted network tunnels.
Vulnerability
This is an information exposure vulnerability (CWE-532) where sensitive pre-shared keys are improperly written to system logs during bulk IPsec policy collection, accessible to users with low-level read permissions.
Business impact
The exposure of pre-shared keys directly undermines the confidentiality and integrity of encrypted network tunnels managed by the SANnav software. With a CVSS score of 8.4, this vulnerability represents a high-severity risk that could lead to unauthorized interception of sensitive data traffic, potentially resulting in significant data breaches and regulatory non-compliance.
Remediation
Immediate Action: Update Brocade SANnav to version 3.0.1a or later to resolve the log sanitization flaw.
Proactive Monitoring: Review access control lists for container logs and support archives to identify unauthorized access attempts by non-administrative users.
Compensating Controls: Restrict access to system logs and sensitive support archives to the absolute minimum number of authorized personnel until the patch can be applied.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high impact of potential network tunnel compromise, organizations must prioritize the transition to version 3.0.1a. Administrators should treat this update as a critical security maintenance task to ensure that sensitive cryptographic material is no longer persisted in plain text within system logs.
More Brocade CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section