{"id":"CVE-2026-85417","title":"Incomplete property masking in the SANnav logging subsystem permits SNMP authentication and privacy passwords to be recorded in application logs under specific configuration conditions","summary":"Incomplete property masking in the SANnav logging subsystem permits SNMP authentication and privacy passwords to be recorded in application logs under specific configuration conditions. Individuals with read access to system logs or supp…","severity":"medium","cvss":6.4,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H","cwe":["CWE-532"],"vendor":"Brocade","product":"SANnav","affected":["SANnav before 3.0.1a"],"published":"2026-09-25","updated":"2026-09-25","sourceUpdated":"2026-09-25T01:16:48.580","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-85417","references":[{"url":"https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/39001","label":"sirt@brocade.com"}],"tags":["nvd","cve.org"],"cvssSource":"cna","ingestedAt":"2026-09-25T00:56:54.276Z","slug":"CVE-2026-85417","body":"## Overview\n\nIncomplete property masking in the SANnav logging subsystem permits SNMP authentication and privacy passwords to be recorded in application logs under specific configuration conditions. Individuals with read access to system logs or support bundles can retrieve these credentials, leading to unauthorized read or management access to monitored switch environments\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":35,"depthScoreParts":{"impact":35.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}