PatchSiren

Brocade CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Brocade CVE published 2026-09-24

CVE-2026-14443

CVE-2026-14443 is a high-severity vulnerability in Brocade SANnav that allows extension switch pre-shared keys to be written to system logs due to incomplete log sanitization during bulk IPsec policy collection. This issue affects Brocade SANnav versions before 3.0.1a. Individuals with read access to container logs or support archives can obtain these keys, potentially compromising encrypted network tunne [truncated]

MEDIUM Brocade CVE published 2026-09-24

CVE-2026-14442

A local or authenticated user with access to application logs or support bundles can view sensitive credentials due to an information exposure vulnerability in SANnav job scheduling component, potentially leading to unauthorized access. This vulnerability allows sensitive parameters, including external server passwords and archive protection keys, to be logged without proper masking, posing a risk to remo [truncated]

MEDIUM Brocade CVE published 2026-09-24

CVE-2026-14441

A logic flaw in Java cache key handling object comparison could lead to improper identifier resolution when processing specific user account structures. The issue has been remediated by updating internal comparison routines. Defenders should assess exposure and prioritize verification of affected systems, especially those handling user accounts. This flaw could lead to potential identity mismatch conditio [truncated]

HIGH Brocade CVE published 2026-09-24

CVE-2026-82372

CVE-2026-82372 debrief: Brocade SANnav versions before 3.0.1a improperly handle sensitive data during IPsec policy creation and modification, potentially exposing pre-shared keys to individuals with read access to system log files or support bundles. This vulnerability requires immediate attention from defenders responsible for Brocade SANnav systems, particularly those with IPsec policies configured, to [truncated]

HIGH Brocade CVE published 2017-01-14

CVE-2016-8207

CVE-2016-8207 is a high-severity directory traversal vulnerability in Brocade Network Advisor’s CliMonitorReportServlet. In affected releases up to and including 14.0.2, a remote attacker could read arbitrary files on the server, including files containing sensitive user information.

HIGH Brocade CVE published 2017-01-14

CVE-2016-8206

CVE-2016-8206 is a directory traversal issue in the SoftwareImageUpload servlet of Brocade Network Advisor. According to NVD, affected versions include Brocade Network Advisor through 14.0.2, and the flaw can let remote attackers write to arbitrary files and, as a consequence, delete files. Because the issue is network-reachable and requires no user interaction, it should be treated as a high-priority fix [truncated]

CRITICAL Brocade CVE published 2017-01-14

CVE-2016-8205

CVE-2016-8205 is a critical directory traversal issue in Brocade Network Advisor’s DashboardFileReceiveServlet. The NVD record says affected versions include those released prior to and including 14.0.2, and that a remote attacker could upload a malicious file into a filesystem location where it can be executed. Because the CVSS vector is network-reachable, requires no privileges, and no user interaction, [truncated]

HIGH Brocade CVE published 2017-01-14

CVE-2016-8201

CVE-2016-8201 describes a cross-site request forgery (CSRF) issue in Brocade Virtual Traffic Manager versions released prior to and including 11.0. In practical terms, an attacker could induce an authenticated user to submit administrative actions against the traffic manager cluster. The NVD record classifies the weakness as CWE-352 and rates it High severity.