CVE-2026-82372
Received Received - Intake

Improper Logging of IPsec Pre-Shared Keys in Brocade SANnav

Vulnerability report for CVE-2026-82372, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-24

Last updated on: 2026-09-24

Assigner: Brocade Communications Systems, LLC

Description

Improper handling of sensitive data during IPsec policy creation and modification in Brocade SANnav versions before 3.0.1a results in pre-shared keys being recorded in application logs. Individuals with read access to system log files or support bundles can view these credentials, leading to the potential exposure of keys used to secure network tunnels.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-24
Last Modified
2026-09-24
Generated
2026-09-25
AI Q&A
2026-09-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
brocade sannav to 3.0.1a (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-532 The product writes sensitive information to a log file.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves improper handling of sensitive data during IPsec policy creation and modification in Brocade SANnav versions before 3.0.1a. Pre-shared keys used to secure network tunnels are recorded in application logs, which can be accessed by individuals with read permissions to system logs or support bundles.

Detection Guidance

Check Brocade SANnav application logs for entries containing pre-shared keys. Search logs for terms like 'key', 'password', or 'secret' in log files or support bundles. Review logs in directories like /var/log/ or application-specific log locations.

Impact Analysis

If exploited, this vulnerability could allow unauthorized individuals to access pre-shared keys used for securing network tunnels. This may lead to network breaches, unauthorized access to sensitive data, or disruption of secure communications.

Mitigation Strategies

Upgrade Brocade SANnav to version 3.0.1a or later. Rotate all IPsec pre-shared keys immediately. Restrict access to system logs and support bundles to authorized personnel only. Review and remove any exposed keys from logs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82372. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart