CVE-2026-5769
Received Received - Intake

Brocade SANnav Plaintext Password Exposure via OOM Condition

Vulnerability report for CVE-2026-5769, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: Brocade Communications Systems, LLC

Description

A vulnerability in Brocade SANnav before 3.0.1 can have the Brocade Fabric OS switch admin password captured in plaintext within a memory swap file on the server hosting the Brocade SANnav Virtual Machine (VM). This can happen when the SANnav server encounters an Out Of Memory (OOM) condition. The vulnerability could allow an authenticated admin user with access to the server hosting the SANnav to potentially view the memory swap file and access the password(s).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Brocade Brocade SANnav 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-313 The product stores sensitive information in cleartext in a file, or on disk.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Brocade SANnav versions before 3.0.1. When the server hosting the SANnav VM runs out of memory, the admin password for Brocade Fabric OS switches may be stored in plaintext within a memory swap file. An authenticated admin with server access could potentially view this file and retrieve the password.

Detection Guidance

Check the Brocade SANnav server for memory swap files containing plaintext admin passwords, especially after an Out Of Memory (OOM) condition occurs. Review system logs for OOM events and inspect swap files on the SANnav VM host.

Impact Analysis

If you use Brocade SANnav before version 3.0.1, an attacker with admin access to the server could capture plaintext passwords for Brocade Fabric OS switches. This could lead to unauthorized access to network switches, potential data breaches, or network compromise.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive admin passwords stored in plaintext within memory swap files on the SANnav server. This may violate compliance requirements under GDPR (data protection) and HIPAA (healthcare data security) by exposing credentials that could be used to access protected systems or data.

Mitigation Strategies

Upgrade Brocade SANnav to version 3.0.1 or later to address the vulnerability. Ensure no plaintext passwords are exposed in memory swap files by reviewing and securing swap file contents. Restrict access to the SANnav server to authorized admin users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-5769. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart