← Vulnerability feed

Vulnerability record · CVE-2020-15377 · published 9 June 2021

CVE-2020-15377: Broadcom sannav server-side request forgery (ssrf) vulnerability

Broadcom · Sannav

Webtools in Brocade SANnav before version 2.1.1 allows unauthenticated users to make requests to arbitrary hosts due to a misconfiguration; this is commonly referred to as Server-Side Request Forgery (SSRF).

9.8 CVSS 3.1 Critical EPSS 1.2% · top 34.3% CWE-918 · Server-side request forgery (SSRF)
9.8CVSS 3.1 base score, v2 7.5
1.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Webtools in Brocade SANnav before version 2.1.1 allows unauthenticated users to make requests to arbitrary hosts due to a misconfiguration; this is commonly referred to as Server-Side Request Forgery (SSRF).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-15377 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-28163Broadcom sannav sql injection vulnerabilityIn Brocade SANnav before Brocade SANnav 2.2.0, multiple endpoints associated with Zone management are susceptible to SQL injection, allowing an attac…EPSS 0.94%8.8CVE-2022-28165Broadcom sannav vulnerabilityA vulnerability in the role-based access control (RBAC) functionality of the Brocade SANNav before 2.2.0 could allow an authenticated, remote attacke…EPSS 1.2%8.5CVE-2025-12772Broadcom sannav cleartext storage of sensitive data vulnerabilityBrocade SANnav before 2.4.0b logs the Brocade Fabric OS Switch admin password on the SANnav support save logs. When OOM occurs on a Brocade SANnav se…EPSS 0.28%7.5CVE-2022-28166Broadcom sannav broken cryptographic algorithm vulnerabilityIn Brocade SANnav version before SANN2.2.0.2 and Brocade SANNav before 2.1.1.8, the implementation of TLS/SSL Server Supports the Use of Static Key C…EPSS 0.57%7.5CVE-2022-28168Broadcom sannav vulnerabilityIn Brocade SANnav before Brocade SANnav v2.2.0.2 and Brocade SANnav2.1.1.8, encoded scp-server passwords are stored using Base64 encoding, which coul…EPSS 0.93%7.5CVE-2020-15380Broadcom sannav sensitive information in log file vulnerabilityBrocade SANnav before version 2.1.1 logs account credentials at the ‘trace’ logging level.EPSS 0.99%7.5CVE-2020-15381Broadcom sannav insufficiently protected credentials vulnerabilityBrocade SANnav before version 2.1.1 contains an Improper Authentication vulnerability that allows cleartext transmission of authentication credential…EPSS 1.0%7.3CVE-2022-2068OpenSSL c_rehash script command injection via unsanitised filenamesThe OpenSSL c_rehash script fails to sanitise shell metacharacters in certificate filenames before passing them to shell commands, allowing OS comman…EPSS 95%analysed

Source: NIST National Vulnerability Database (record CVE-2020-15377), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.