Vulnerability Intelligence Report
Brocade SANnav encryption key is logged in the debug logs
CVE-2025-1053
Under certain error conditions at time of SANnav installation or upgrade, the encryption key can be written into and obtained from a Brocade SANnav supportsave. An attacker with privileged access to the Brocade SANnav database could use the encryption key to obtain passwords used by Brocade SANnav.
No Active Exploit Signals
CVSS Base Score
8.6
HIGH
EPSS Probability:0.14%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-532 ↗CWE-532 Insertion of Sensitive Information into Log File
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Brocade | Brocade SANnav | Brocade SANnav before 2.3.1b (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.145%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Brocade Communications Systems LLC, a Broadcom Company · Vendor · USA |
| Reserved | 2025-02-04T22:50:57 |
| Published | 2025-02-14T03:47:35 |
| Last Updated | 2025-09-09T19:03:10 |
Community Chatter & Buzz