Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2025-12679

Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-312 Almacenamiento de información sensible en texto claro
Fecha de publicación:
02/02/2026
Última modificación:
02/02/2026

Descripción

*** Pendiente de traducción *** A vulnerability in Brocade SANnav before 2.4.0b prints the <br /> Password-Based Encryption (PBE) key in plaintext in the system audit log<br /> file. The vulnerability could allow a remote authenticated attacker <br /> with access to the audit logs to access the pbe key.<br /> <br /> Note: The vulnerability is only triggered during a migration and not <br /> in a new installation. The system audit logs are accessible only to a <br /> privileged user on the server.<br /> <br /> <br /> <br /> These audit logs are the local server VM’s audit logs and are not <br /> controlled by SANnav. These logs are only visible to the server admin of<br /> the host server and are not visible to the SANnav admin or any SANnav <br /> user.