Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2567▼ 333 respecto a la semana anterior
Críticas / altas1341▲ 75 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
–

148 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.4)0.11%—Brocade SannavAI24/9/20261/10/2026
Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav versions before 3.0.1a permit extension switch pre-shared keys to be written to system logs. Individuals with read access to container logs or support archives can obtain these keys, leading to the potential compromise of encrypted…
Pendiente de análisisAlta (8.5)0.17%—Brocade SannavAI24/9/20261/10/2026
Improper handling of sensitive data during IPsec policy creation and modification in Brocade SANnav versions before 3.0.1a results in pre-shared keys being recorded in application logs. Individuals with read access to system log files or support bundles can view these credentials, leading to the potential exposure of…
Pendiente de análisisAlta (8.5)0.13%—Brocade SannavAI24/9/20261/10/2026
Plaintext exposure of sensitive authentication data in Brocade SANnav discovery service log files enables individuals with file read access to retrieve administrative switch credentials and active session tokens. An attacker with access to system logs or support bundles can leverage exposed authentication details to…
Pendiente de análisisAlta (8.6)0.60%—Brocade SannavAI23/9/20261/10/2026
Unauthenticated remote command injection in the Brocade SANnav orchestrator HTTP service permits network-adjacent attackers to execute arbitrary administrative switch CLI commands and issue container management instructions. This could allow an attacker to alter Fibre Channel fabric switch configurations or manipulate…
Pendiente de análisisAlta (8.6)0.51%—Brocade SannavAI23/9/20261/10/2026
Insufficient input sanitization of shell metacharacters in the Brocade SANnav CLI scripting component permits authenticated users to break out of restricted execution contexts on managed switches. An attacker with command execution permissions can leverage this flaw to run unauthorized shell commands across target…
Pendiente de análisisAlta (8.7)0.25%—Brocade SannavAI23/9/20261/10/2026
Insecure access controls on internal service ports in Brocade SANnav versions before 3.0.1a allow local, non-administrative host users to communicate directly with backend management services. A local attacker can leverage this exposed access to transmit commands to connected Fabric OS switches under the security…
AnalizadaAlta (8.3)0.40%—Broadcom Brocade Active Support Connectivity Gateway3/3/202617/6/2026
Authentication bypass in Brocade ASCG 3.4.0 Could allow an unauthorized user to perform ASCG operations related to Brocade Support Link(BSL) and streaming configuration. and could even disable the ASCG application or disable use of BSL data collection on Brocade switches within the fabric.
AnalizadaAlta (8.6)0.16%—Broadcom Brocade Active Support Connectivity Gateway17/7/202517/6/2026
Brocade ASCG before 3.3.0 allows for the use of medium strength cryptography algorithms on internal ports ports 9000 and 8036.
AnalizadaMedia (6.8)0.10%—Brocade Ascg17/7/202517/6/2026
A vulnerability in the ascgshell, of Brocade ASCG before 3.3.0 stores any command executed in the Command Line Interface (CLI) in plain text within the command history. A local authenticated user that can access sensitive information like passwords within the CLI history leading to unauthorized access and potential…
AnalizadaAlta (7.1)0.24%—Broadcom Brocade Active Support Connectivity Gateway17/7/202517/6/2026
Brocade ASCG before 3.3.0 logs JSON Web Tokens (JWT) in log files. An attacker with access to the log files can withdraw the unencrypted tokens with security implications, such as unauthorized access, session hijacking, and information disclosure.
AnalizadaMedia (6.7)0.14%—Broadcom Brocade Sannav10/7/202517/6/2026
Brocade SANnav before Brocade SANnav 2.4.0a could log database passwords in clear text in audit logs when the daily data dump collector invokes docker exec commands. These audit logs are the local server VM’s audit logs and are not controlled by SANnav. These logs are only visible to the server admin of the host…
AnalizadaMedia (5.1)0.14%—Broadcom Brocade Sannav10/7/202517/6/2026
Brocade SANnav before SANnav 2.4.0a logs passwords and pbe keys in the Brocade SANnav server audit logs after installation and under specific conditions. These audit logs are the local server VM’s audit logs and are not controlled by SANnav. These logs are only visible to the server admin of the host server and are…
AnalizadaMedia (5.1)0.14%—Broadcom Brocade Sannav10/7/202517/6/2026
Brocade SANnav before SANnav 2.4.0a logs plaintext passphrases in the Brocade SANnav host server audit logs while executing OpenSSL command using a passphrase from the command line or while providing the passphrase through a temporary file. These audit logs are the local server VM’s audit logs and are not controlled…
AnalizadaAlta (7.6)0.37%—Broadcom Brocade Active Support Connectivity Gateway28/2/202517/6/2026
Brocade ASCG before 3.2.0 Web Interface is not enforcing HSTS, as defined by RFC 6797. HSTS is an optional response header that can be configured on the server to instruct the browser to only communicate via HTTPS. The lack of HSTS allows downgrade attacks, SSL-stripping man-in-the-middle attacks, and weakens…
AnalizadaAlta (8.2)0.29%—Broadcom Brocade Sannav15/2/202517/6/2026
Brocade SANnav OVA before SANnav 2.3.1b enables SHA1 deprecated setting for SSH for port 22.
AnalizadaMedia (6.9)0.20%—Broadcom Brocade Sannav15/2/202517/6/2026
Brocade SANnav before SANnav 2.3.1b enables weak TLS ciphers on ports 443 and 18082. In case of a successful exploit, an attacker can read Brocade SANnav data stream that includes monitored Brocade Fabric OS switches performance data, port status, zoning information, WWNs, IP Addresses, but no customer data, no…
AnalizadaAlta (8.6)0.51%—Broadcom Brocade Sannav14/2/202517/6/2026
Docker daemon in Brocade SANnav before SANnav 2.3.1b runs without auditing. The vulnerability could allow a remote authenticated attacker to execute various attacks.
AnalizadaAlta (8.6)0.16%—Broadcom Brocade Sannav14/2/202517/6/2026
Under certain error conditions at time of SANnav installation or upgrade, the encryption key can be written into and obtained from a Brocade SANnav supportsave. An attacker with privileged access to the Brocade SANnav database could use the encryption key to obtain passwords used by Brocade SANnav.
AnalizadaMedia (4.4)0.11%—Broadcom Brocade Sannav14/2/202517/6/2026
CalInvocationHandler in Brocade SANnav before 2.3.1b logs sensitive information in clear text. The vulnerability could allow an authenticated, local attacker to view Brocade Fabric OS switch sensitive information in clear text. An attacker with administrative privileges could retrieve sensitive information including…
AnalizadaMedia (4.8)1.0%—Oracle GraalvmOracle Graalvm FOR JDKOracle JDKOracle JRE+721/1/202517/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u431-perf, 11.0.25, 17.0.13, 21.0.5, 23.0.1; Oracle GraalVM for JDK: 17.0.13, 21.0.5, 23.0.1; Oracle GraalVM…
AnalizadaMedia (5.5)0.46%—Broadcom Brocade Sannav21/11/202417/6/2026
Possible information exposure through log file vulnerability where sensitive fields are recorded in the debug-enabled logs when debugging is turned on in Brocade SANnav before 2.3.0 and 2.2.2a
AnalizadaMedia (4.9)0.78%—Broadcom Brocade Sannav21/11/202417/6/2026
Brocade SANnav versions before 2.2.2 log Brocade Fabric OS switch passwords when debugging is enabled.
AnalizadaMedia (4.4)0.22%—Broadcom Brocade Sannav21/11/202417/6/2026
An information exposure through log file vulnerability exists in Brocade SANnav before Brocade SANnav 2.2.2, where Brocade Fabric OS Switch passwords and authorization IDs are printed in the embedded MLS DB file.
AnalizadaAlta (7.5)0.48%—Broadcom Brocade Sannav21/11/202417/6/2026
Brocade SANnav before Brocade SANnav 2.2.2 supports key exchange algorithms, which are considered weak on ports 24, 6514, 18023, 19094, and 19095.
AnalizadaMedia (4.4)0.26%—Broadcom Brocade Sannav21/11/202417/6/2026
An information exposure through log file vulnerability exists in Brocade SANnav before Brocade SANnav 2.2.2, where configuration secrets are logged in supportsave. Supportsave file is generated by an admin user troubleshooting the switch. The Logged information may include usernames and passwords, and secret keys.