CVE-2025-12679 - CVE House
Back to Database
Status published High CVE-2025-12679

Plain text pbe key visible in audit log during Brocade SANnav migration from 2.4.0a to 3.0.0

Vulnerability Description

A vulnerability in Brocade SANnav before 2.4.0b prints the Password-Based Encryption (PBE) key in plaintext in the system audit log file. The vulnerability could allow a remote authenticated attacker with access to the audit logs to access the pbe key. Note: The vulnerability is only triggered during a migration and not in a new installation. The system audit logs are accessible only to a privileged user on the server. These audit logs are the local server VM’s audit logs and are not controlled by SANnav. These logs are only visible to the server admin of the host server and are not visible to the SANnav admin or any SANnav user.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-12679

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

SANnav
Vulnerable Versions:
SANnav before 2.4.0b

Timeline

Official Publish: February 2nd, 2026
Last Modified: February 4th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)