Brocade Sannav

Vendor:

First CVE: Nov 8, 2019 · Active for 6 years

54
Total CVEs
More Total CVEs than 98% of tracked products
7.7
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Brocade Sannav over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 8, 2019
6 years ago
Most Recent CVE
Jul 10, 2025
383 days ago

CVE Severity & Scoring

Brocade Sannav54 CVEs
All CVEs353,173 CVEs
LowMediumHighCritical
Attack Vector
Local18 (33.3%)
Network34 (63.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (3.7%)
Attack Complexity
Low49 (90.7%)
High5 (9.3%)
Unknown0 (0.0%)
User Interaction
None50 (92.6%)
Unknown0 (0.0%)
Required4 (7.4%)
Privileges Required
Low17 (31.5%)
High13 (24.1%)
None24 (44.4%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (54 CVEs).

54 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message conv
Jan 18, 20229.868NONO
JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration refere
Jan 18, 20228.863NONO
RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any ot
Jul 9, 20249.038NONO
Brocade SANnav versions before v2.1.0, contain a Plaintext Password Storage vulnerability.
Sep 25, 20209.828NONO
A vulnerability in Brocade SANnav exposes Kafka in the wan interface. The vulnerability could allow an unauthenticated attacker to perform various attacks, including DOS against
Apr 25, 20249.827NONO
Brocade SANnav OVA before v2.3.1 and v2.3.0a contain hard-coded credentials in the documentation that appear as the appliance's root password. The vulnerability could allow an unau
Apr 19, 20249.827NONO
A vulnerability, in Brocade SANnav versions before v2.0, could allow remote attackers to brute-force a valid session ID. The vulnerability is due to an insufficiently random sessio
Nov 8, 20198.827NONO
Brocade SANnav OVA before SANnav 2.3.1b enables SHA1 deprecated setting for SSH for port 22.
Feb 15, 20259.826NONO
Brocade SANnav Web interface before Brocade SANnav v2.3.0 and v2.2.2a allows remote unauthenticated users to bypass web authentication and authorization.
Aug 31, 20239.826NONO
A vulnerability in Brocade SANnav versions before v2.1.0 could allow a remote authenticated attacker to conduct an LDAP injection. The vulnerability could allow a remote attacker t
Sep 25, 20208.825NONO

Exploit Exposure

Signals from CVEs in this product scope (54 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (54 CVEs).

Media Mentions

Signals from CVEs in this product scope (54 CVEs).

Top CNAs Publishing CVEs For Brocade Sannav

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.3.117.80.2%00