CVE-2026-14443
Received Received - Intake

Incomplete Log Sanitization in Brocade SANnav Exposes IPsec Pre-Shared Keys

Vulnerability report for CVE-2026-14443, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-24

Last updated on: 2026-09-24

Assigner: Brocade Communications Systems, LLC

Description

Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav versions before 3.0.1a permit extension switch pre-shared keys to be written to system logs. Individuals with read access to container logs or support archives can obtain these keys, leading to the potential compromise of encrypted network tunnels.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-24
Last Modified
2026-09-24
Generated
2026-09-25
AI Q&A
2026-09-25
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
brocade sannav to 3.0.1a (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-532 The product writes sensitive information to a log file.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves incomplete log sanitization in Brocade SANnav versions before 3.0.1a during bulk IPsec policy collection. It allows extension switch pre-shared keys to be written to system logs. Attackers with read access to container logs or support archives could extract these keys and potentially compromise encrypted network tunnels.

Detection Guidance

Check Brocade SANnav container logs for exposed pre-shared keys. Search logs for IPsec policy collection entries or sensitive key material. Use commands like 'docker logs <container_name>' or 'kubectl logs <pod_name>' to inspect logs. Look for plaintext keys in log files or support archives.

Impact Analysis

If you use Brocade SANnav versions before 3.0.1a, an attacker with log access could obtain pre-shared keys for IPsec tunnels. This could lead to unauthorized access to encrypted network communications, data breaches, or man-in-the-middle attacks on your network infrastructure.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data transmitted over IPsec tunnels, potentially violating GDPR (data protection) and HIPAA (health information privacy) requirements. Organizations may face compliance violations, fines, or legal consequences if such breaches occur due to inadequate security measures.

Mitigation Strategies

Upgrade Brocade SANnav to version 3.0.1a or later. Restrict access to container logs and support archives. Rotate all IPsec pre-shared keys if they may have been exposed. Review and sanitize existing logs to remove any exposed keys.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14443. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart