CVEs we hold for Brocade
Records whose assigning authority named Brocade as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-0869Application User custom defined accounts are not properly password protected in Brocade ASCG 3.4.0Brocade ASCG
CVE-2026-0383Information disclosure in Brocade Fabric OS before 9.2.1c2, 9.2.2 through 9.2.2a and 10.0.0Brocade Fabric OS
CVE-2025-9711Privilege escalation in Brocade Fabric OS before 9.2.1c3, and 9.2.2 though 9.2.2bBrocade Fabric OS
CVE-2025-58382Privilege escalation in Brocade Fabric before 9.2.1c2 and 9.2.2 through 9.2.2aBrocade Fabric OS
CVE-2025-58381Directory transversal vulnerability in Brocade Fabric OS before 9.2.1c2 and 9.2.2 through 9.2.2a using various shell…Brocade Fabric OS
CVE-2025-58380Directory transversal vulnerability in Brocade Fabric OS before 9.2.1 using grep commandBrocade Fabric OS
CVE-2025-4661Path transversal vulnerability potentially leading to sensitive information disclosureBrocade Fabric OS
CVE-2025-12774SQL queries with sensitive information printed in logs with Brocade SANnav before 3.0Brocade SANnav
CVE-2025-12773Plain password is generated in the audit logs while executing update-reports-purge-settings.sh script with Brocade…Brocade SANnav
CVE-2025-12772Plaintext Switch admin login password is seen in Brocade SANnav support saveBrocade SANnav
CVE-2025-12680Brocade SANnav DataBase plaintext password is logged in failover logs (CVE-2025-12680)Brocade SANnav
CVE-2025-12679Plain text pbe key visible in audit log during Brocade SANnav migration from 2.4.0a to 3.0.0Brocade SANnav
CVE-2024-7516Brocade Fabric OS before 9.2.2 does not enforce strict host key checkingBrocade Fabric OS
CVE-2024-5461Command or parameter injection via unique embedded switch SNMP commands.Brocade Fabric OS
CVE-2024-5460Brocade Fabric OS versions prior to v9.0 have default community stringsBrocade Fabric OS
CVE-2024-29969TLS/SSL weak message authentication code ciphers are added by default for port 18082Brocade SANnav
CVE-2024-29968SQL Table names, column names, and SQL queries are collected in DR standby SupportsaveBrocade SANnav
CVE-2024-29967In Brocade SANnav before v2.31 and v2.3.0a, it was observed that Docker instances inside the appliance have insecure…Brocade SANnav
CVE-2024-29966hard-coded credentials in the documentation that appear as the appliance root passwordBrocade SANnav
CVE-2024-29964Brocade SANnav versions before v2.3.0a do not correctly set permissions on files, including docker filesBrocade SANnav
CVE-2024-29959Brocade Fabric OS switch encrypted passwords in the Brocade SANnav Standby node's support saveBrocade SANnav
CVE-2024-29958Encryption key in the console when a privileged user executes the script to replace the Brocade SANnav Management…Brocade SANnav
CVE-2024-29956cleartext password in supportsave logs when a user schedules a switch Supportsave from Brocade SANnavBrocade SANnav
CVE-2024-29953Encoded session passwords on session storage for Virtual Fabric platformsBrocade Fabric OS
CVE-2024-29952Clear text storage of sensistive information by manipulating command variablesBrocade SANnav
CVE-2024-2859By default, SANnav OVA is shipped with root user login enabled (CVE-2024-2859)Brocade SANnav
CVE-2024-1509Brocade ASCG 3.2.0 web interface does not enforce HSTS, as defined by RFC 6797 for ports 8030 and 8100Brocade ASCG
CVE-2024-10404Clear text password seen in switch-asset-collectors-mw in Brocade SANnav supportsaveBrocade SANnav
CVE-2024-10403SFTP/FTP password could be captured in plain text in Supportsave generated from SANnavBrocade Fabric OS
CVE-2022-43935Switch passwords and authorization IDs are printed in the embedded MLS DB fileBrocade SANnav
CVE-2022-33187Brocade SANnav before v2.2.1 logs usernames and encoded passwords in debug-enabled logsBrocade SANnav
CVE-2021-27798privileged directory transversal.in Brocade Fabric OS versions 7.4.1.x and 7.3.xBrocade Fabric OS
CVE-2021-27795License forgery in Brocade Fabric OS (FOS) hardware platforms running any version of Brocade Fabric OS software,Brocade Switches
167 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.