CVE-2025-12679
Severity CVSS v4.0:
HIGH
Type:
CWE-312
Cleartext Storage of Sensitive Information
Publication date:
02/02/2026
Last modified:
02/02/2026
Description
A vulnerability in Brocade SANnav before 2.4.0b prints the <br />
Password-Based Encryption (PBE) key in plaintext in the system audit log<br />
file. The vulnerability could allow a remote authenticated attacker <br />
with access to the audit logs to access the pbe key.<br />
<br />
Note: The vulnerability is only triggered during a migration and not <br />
in a new installation. The system audit logs are accessible only to a <br />
privileged user on the server.<br />
<br />
<br />
<br />
These audit logs are the local server VM’s audit logs and are not <br />
controlled by SANnav. These logs are only visible to the server admin of<br />
the host server and are not visible to the SANnav admin or any SANnav <br />
user.
Impact
Base Score 4.0
7.10
Severity 4.0
HIGH



