Vulnerability Description
Brocade SANnav before Brocade SANnav 2.4.0b logs database passwords in clear text in the standby SANnav server, after disaster recovery failover. The vulnerability could allow a remote authenticated attacker with admin privilege able to access the SANnav logs or the supportsave to read the database password.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Broadcom | Sannav | < 2.4.0b |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-12680?
CVE-2025-12680 is a vulnerability with a CVSS score of 4.9 (MEDIUM). Brocade SANnav before Brocade SANnav 2.4.0b logs database passwords in clear text in the standby SANnav server, after disaster recovery failover. The vulnerability could allow a remote authenticated ...
How severe is CVE-2025-12680?
CVE-2025-12680 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-12680?
Check the references section above for vendor advisories and patch information. Affected products include: Broadcom Sannav.