Brocade SANnav before Brocade SANnav 2.4.0b logs database passwords in clear text in the standby SANnav server, after disaster recovery failover. The vulnerability could allow a remote authenticated attacker with admin privilege able to access the SANnav logs or the supportsave to read the database password.
Metrics
Affected Vendors & Products
References
History
Mon, 02 Feb 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Brocade SANnav before Brocade SANnav 2.4.0b logs database passwords in clear text in the standby SANnav server, after disaster recovery failover. The vulnerability could allow a remote authenticated attacker with admin privilege able to access the SANnav logs or the supportsave to read the database password. | |
| Title | Brocade SANnav DataBase plaintext password is logged in failover logs (CVE-2025-12680) | |
| Weaknesses | CWE-256 CWE-312 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: brocade
Published:
Updated: 2026-02-03T02:01:06.938Z
Reserved: 2025-11-03T23:43:51.547Z
Link: CVE-2025-12680
No data.
Status : Received
Published: 2026-02-02T23:15:58.280
Modified: 2026-02-02T23:15:58.280
Link: CVE-2025-12680
No data.
OpenCVE Enrichment
No data.