Back to Database
Status published
Medium
CVE-2024-29955
Insertion of Sensitive Information into Brocade SANnav Log File
Vulnerability Description
A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow a privileged user to print the SANnav encrypted key in PostgreSQL startup logs. This could provide attackers with an additional, less-protected path to acquiring the encryption key.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-29955
Credits & Attribution
No credits recorded in the NVD database.
More from Brocade
View All →CVE-2025-9711
Privilege escalation in Brocade Fabric OS before 9.2.1c3, and 9.2.2 though 9.2.2b
High
8.5
CVE-2025-58383
Privilege escalation via bind command in Brocade Fabric OS
High
8.4
CVE-2025-58382
Privilege escalation in Brocade Fabric before 9.2.1c2 and 9.2.2 through 9.2.2a
High
8.5
CVE-2025-58381
Directory transversal vulnerability in Brocade Fabric OS before 9.2.1c2 and 9.2.2 through 9.2.2a using various shell commands
Medium
4.6
CVE-2025-58380
Directory transversal vulnerability in Brocade Fabric OS before 9.2.1 using grep command
Medium
4.6
Affected Vendor
Brocade
View all reports →Affected Software
Brocade SANnav
Vulnerable Versions:
before v2.3.1 and v2.3.0a
Timeline
Official Publish:
April 17th, 2024
Last Modified:
August 2nd, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N