CVE-2025-12679

Severity CVSS v4.0:
HIGH
Type:
CWE-312 Cleartext Storage of Sensitive Information
Publication date:
02/02/2026
Last modified:
02/02/2026

Description

A vulnerability in Brocade SANnav before 2.4.0b prints the <br /> Password-Based Encryption (PBE) key in plaintext in the system audit log<br /> file. The vulnerability could allow a remote authenticated attacker <br /> with access to the audit logs to access the pbe key.<br /> <br /> Note: The vulnerability is only triggered during a migration and not <br /> in a new installation. The system audit logs are accessible only to a <br /> privileged user on the server.<br /> <br /> <br /> <br /> These audit logs are the local server VM’s audit logs and are not <br /> controlled by SANnav. These logs are only visible to the server admin of<br /> the host server and are not visible to the SANnav admin or any SANnav <br /> user.