Brocade Sannav
Vendor:
First CVE: Nov 8, 2019 · Active for 6 years
54
Total CVEs
More Total CVEs than 98% of tracked products
7.7
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Brocade Sannav over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 8, 2019
6 years ago
Most Recent CVE
Jul 10, 2025
383 days ago
CVE Severity & Scoring
Brocade Sannav54 CVEs
50%
35%
13%
All CVEs353,173 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local18 (33.3%)
Network34 (63.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (3.7%)
Attack Complexity
Low49 (90.7%)
High5 (9.3%)
Unknown0 (0.0%)
User Interaction
None50 (92.6%)
Unknown0 (0.0%)
Required4 (7.4%)
Privileges Required
Low17 (31.5%)
High13 (24.1%)
None24 (44.4%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (54 CVEs).
54 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-23305CRITICAL By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message conv | Jan 18, 2022 | 9.8 | 68 | NO | NO |
CVE-2022-23302HIGH JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration refere | Jan 18, 2022 | 8.8 | 63 | NO | NO |
CVE-2024-3596CRITICAL RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any ot | Jul 9, 2024 | 9.0 | 38 | NO | NO |
CVE-2019-16211CRITICAL Brocade SANnav versions before v2.1.0, contain a Plaintext Password Storage vulnerability. | Sep 25, 2020 | 9.8 | 28 | NO | NO |
CVE-2024-4173CRITICAL
A vulnerability in Brocade SANnav exposes Kafka in the wan interface.
The vulnerability could allow an unauthenticated attacker to perform various attacks, including DOS against | Apr 25, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-29966CRITICAL Brocade SANnav OVA before v2.3.1 and v2.3.0a contain hard-coded credentials in the documentation that appear as the appliance's root password. The vulnerability could allow an unau | Apr 19, 2024 | 9.8 | 27 | NO | NO |
CVE-2019-16205HIGH A vulnerability, in Brocade SANnav versions before v2.0, could allow remote attackers to brute-force a valid session ID. The vulnerability is due to an insufficiently random sessio | Nov 8, 2019 | 8.8 | 27 | NO | NO |
CVE-2024-4282CRITICAL Brocade SANnav OVA before SANnav 2.3.1b enables SHA1 deprecated setting for SSH for port 22. | Feb 15, 2025 | 9.8 | 26 | NO | NO |
CVE-2023-31424CRITICAL Brocade SANnav Web interface before Brocade SANnav v2.3.0 and v2.2.2a
allows remote unauthenticated users to bypass web authentication and
authorization. | Aug 31, 2023 | 9.8 | 26 | NO | NO |
CVE-2019-16212HIGH A vulnerability in Brocade SANnav versions before v2.1.0 could allow a remote authenticated attacker to conduct an LDAP injection. The vulnerability could allow a remote attacker t | Sep 25, 2020 | 8.8 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (54 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (54 CVEs).
Media Mentions
Signals from CVEs in this product scope (54 CVEs).
Top CNAs Publishing CVEs For Brocade Sannav
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.3.1 | 1 | 7.8 | 0.2% | 0 | 0 |