CVE-2026-82372

8.5

Brocade · SANnav

Brocade SANnav incorrectly logs sensitive IPsec pre-shared keys, allowing authenticated users with log access to compromise credentials and potentially intercept network tunnel traffic.

Executive summary

A high-severity vulnerability in Brocade SANnav allows authenticated users to access sensitive IPsec pre-shared keys stored in system logs, posing a significant risk to network tunnel security.

Vulnerability

This vulnerability involves the improper insertion of sensitive information into log files (CWE-532). The system records IPsec pre-shared keys during policy configuration, permitting any authenticated user with read access to log files or support bundles to extract these credentials.

Business impact

The exposure of IPsec pre-shared keys allows unauthorized parties to compromise the confidentiality of encrypted network tunnels. Given the CVSS score of 8.5, this high-severity flaw could lead to data interception, unauthorized network access, and a total loss of confidentiality for sensitive traffic traversing the affected SAN infrastructure.

Remediation

Immediate Action: Upgrade to Brocade SANnav version 3.0.1a or later to prevent the logging of sensitive credentials.

Proactive Monitoring: Review existing system logs and support bundles for legacy entries containing pre-shared keys, and restrict access to log directories to authorized administrators only.

Compensating Controls: Implement strict access control lists on log storage directories and rotate all existing IPsec keys if there is a suspicion that logs have been accessed by unauthorized personnel.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit in the available data.

Analyst recommendation

This vulnerability presents a clear risk to the integrity of network communications managed by Brocade SANnav. Security teams must prioritize patching to version 3.0.1a to eliminate the exposure of sensitive keys. Following the update, organizations should audit access logs to identify any unauthorized attempts to view system configuration files or support bundles.

More Brocade CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources