Sannav
Vendor:
First CVE: Jun 2, 2020 · Active for 6 years
20
Total CVEs
More Total CVEs than 94% of tracked products
5.0
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Sannav over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 2, 2020
6 years ago
Most Recent CVE
Feb 3, 2026
173 days ago
CVE Severity & Scoring
Sannav20 CVEs
50%
35%
10%
All CVEs352,719 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (10.0%)
Network18 (90.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (95.0%)
High1 (5.0%)
Unknown0 (0.0%)
User Interaction
None19 (95.0%)
Unknown0 (0.0%)
Required1 (5.0%)
Privileges Required
Low9 (45.0%)
High2 (10.0%)
None9 (45.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2068HIGH In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to | Jun 21, 2022 | 7.3 | 76 | NO | NO |
CVE-2022-28163CRITICAL In Brocade SANnav before Brocade SANnav 2.2.0, multiple endpoints associated with Zone management are susceptible to SQL injection, allowing an attacker to run arbitrary SQL comman | May 6, 2022 | 9.8 | 29 | NO | NO |
CVE-2022-28165HIGH A vulnerability in the role-based access control (RBAC) functionality of the Brocade SANNav before 2.2.0 could allow an authenticated, remote attacker to access resources that they | May 6, 2022 | 8.8 | 28 | NO | NO |
CVE-2025-12774HIGH A vulnerability in the migration script for Brocade SANnav before 3.0 could allow the collection of database sql queries in the SANnav support save file. An attacker with access to | Feb 3, 2026 | 7.5 | 24 | NO | NO |
CVE-2022-28166HIGH In Brocade SANnav version before SANN2.2.0.2 and Brocade SANNav before 2.1.1.8, the implementation of TLS/SSL Server Supports the Use of Static Key Ciphers (ssl-static-key-ciphers) | Jun 27, 2022 | 7.5 | 24 | NO | NO |
CVE-2020-15377CRITICAL Webtools in Brocade SANnav before version 2.1.1 allows unauthenticated users to make requests to arbitrary hosts due to a misconfiguration; this is commonly referred to as Server-S | Jun 9, 2021 | 9.8 | 24 | NO | NO |
CVE-2025-12773MEDIUM A vulnerability in update-reports-purge-settings.sh script logging for Brocade SANnav before 2.4.0a could allow the collection of SANnav database password in the system audit logs. | Feb 3, 2026 | 6.5 | 22 | NO | NO |
CVE-2020-15381HIGH Brocade SANnav before version 2.1.1 contains an Improper Authentication vulnerability that allows cleartext transmission of authentication credentials of the jmx server. | Jun 9, 2021 | 7.5 | 22 | NO | NO |
CVE-2020-13401MEDIUM An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements, and consequently spoof | Jun 2, 2020 | 6.0 | 22 | NO | NO |
CVE-2025-12679MEDIUM A vulnerability in Brocade SANnav before 2.4.0b prints the
Password-Based Encryption (PBE) key in plaintext in the system audit log
file. The vulnerability could allow a remote a | Feb 2, 2026 | 6.5 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (20 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (20 CVEs).
Media Mentions
Signals from CVEs in this product scope (20 CVEs).
Top CNAs Publishing CVEs For Sannav
Top CWEs
Versions
No cataloged versions.