← Vulnerability feed

Vulnerability record · CVE-2025-12679 · published 2 February 2026

CVE-2025-12679: Broadcom sannav cleartext storage of sensitive data vulnerability

Broadcom · Sannav

A vulnerability in Brocade SANnav before 2.4.0b prints the Password-Based Encryption (PBE) key in plaintext in the system audit log file. The vulnerability could allow a remote authenticated attacker with access to the audit logs to access the pbe key. Note: The vulnerability is only triggered during a migration and not in a new installation. The system audit logs are accessible only to a privileged user on the server. These audit logs are the local server VM’s audit logs and are not controlled by SANnav. These logs are only visible to the server admin of the host server and are not visible to the SANnav admin or any SANnav user.

7.1 CVSS 4.0 High EPSS 0.15% · top 96.1% CWE-312 · Cleartext storage of sensitive data
7.1CVSS 4.0 base score
0.15%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

A vulnerability in Brocade SANnav before 2.4.0b prints the Password-Based Encryption (PBE) key in plaintext in the system audit log file. The vulnerability could allow a remote authenticated attacker with access to the audit logs to access the pbe key. Note: The vulnerability is only triggered during a migration and not in a new installation. The system audit logs are accessible only to a privileged user on the server. These audit logs are the local server VM’s audit logs and are not controlled by SANnav. These logs are only visible to the server admin of the host server and are not visible to the SANnav admin or any SANnav user.

CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:P/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-12679 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-28163Broadcom sannav sql injection vulnerabilityIn Brocade SANnav before Brocade SANnav 2.2.0, multiple endpoints associated with Zone management are susceptible to SQL injection, allowing an attac…EPSS 0.94%9.8CVE-2020-15377Broadcom sannav server-side request forgery (ssrf) vulnerabilityWebtools in Brocade SANnav before version 2.1.1 allows unauthenticated users to make requests to arbitrary hosts due to a misconfiguration; this is c…EPSS 1.2%8.8CVE-2022-28165Broadcom sannav vulnerabilityA vulnerability in the role-based access control (RBAC) functionality of the Brocade SANNav before 2.2.0 could allow an authenticated, remote attacke…EPSS 1.2%8.5CVE-2025-12772Broadcom sannav cleartext storage of sensitive data vulnerabilityBrocade SANnav before 2.4.0b logs the Brocade Fabric OS Switch admin password on the SANnav support save logs. When OOM occurs on a Brocade SANnav se…EPSS 0.28%7.5CVE-2022-28166Broadcom sannav broken cryptographic algorithm vulnerabilityIn Brocade SANnav version before SANN2.2.0.2 and Brocade SANNav before 2.1.1.8, the implementation of TLS/SSL Server Supports the Use of Static Key C…EPSS 0.57%7.5CVE-2022-28168Broadcom sannav vulnerabilityIn Brocade SANnav before Brocade SANnav v2.2.0.2 and Brocade SANnav2.1.1.8, encoded scp-server passwords are stored using Base64 encoding, which coul…EPSS 0.93%7.5CVE-2020-15380Broadcom sannav sensitive information in log file vulnerabilityBrocade SANnav before version 2.1.1 logs account credentials at the ‘trace’ logging level.EPSS 0.99%7.5CVE-2020-15381Broadcom sannav insufficiently protected credentials vulnerabilityBrocade SANnav before version 2.1.1 contains an Improper Authentication vulnerability that allows cleartext transmission of authentication credential…EPSS 1.0%

Source: NIST National Vulnerability Database (record CVE-2025-12679), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.