CVE-2025-12773: Plain password is generated in the audit logs while executing update-reports-purge-settings.sh script with Brocade SANnav before 2.4.0a
A vulnerability in update-reports-purge-settings.sh script logging for Brocade SANnav before 2.4.0a could allow the collection of SANnav database password in the system audit logs. The vulnerability could allow a remote authenticated attacker with access to the audit logs to access the Brocade SANnav database password.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12773?
CVE-2025-12773 is considered a high-severity vulnerability due to the exposure of sensitive database credentials.
How do I fix CVE-2025-12773?
To fix CVE-2025-12773, upgrade Brocade SANnav to version 2.4.0a or later.
What vulnerability does CVE-2025-12773 relate to?
CVE-2025-12773 relates to the logging of plain passwords in audit logs when using the update-reports-purge-settings.sh script.
What software is affected by CVE-2025-12773?
The affected software is Brocade SANnav versions before 2.4.0a.
What could an attacker do with the information from CVE-2025-12773?
An attacker could utilize the plain password logged in the audit logs to gain unauthorized access to the SANnav database.