{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-14443",
        "assignerOrgId": "87b297d7-335e-4844-9551-11b97995a791",
        "state": "PUBLISHED",
        "assignerShortName": "brocade",
        "dateReserved": "2026-07-01T23:05:44.125Z",
        "datePublished": "2026-09-24T20:06:28.925Z",
        "dateUpdated": "2026-09-24T20:06:28.925Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "87b297d7-335e-4844-9551-11b97995a791",
                "shortName": "brocade",
                "dateUpdated": "2026-09-24T20:06:28.925Z"
            },
            "title": "Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav before 3.0.1a",
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "cweId": "CWE-532",
                            "description": "CWE-532 Insertion of sensitive information into log file",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "impacts": [
                {
                    "capecId": "CAPEC-215",
                    "descriptions": [
                        {
                            "lang": "en",
                            "value": "CAPEC-215 Fuzzing for application mapping"
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "vendor": "Brocade",
                    "product": "SANnav",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "before 3.0.1.a"
                        }
                    ],
                    "defaultStatus": "affected"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "value": "Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav versions before 3.0.1a permit extension switch pre-shared keys to be written to system logs. Individuals with read access to container logs or support archives can obtain these keys, leading to the potential compromise of encrypted network tunnels.",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "<span>Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav versions before 3.0.1a permit extension switch pre-shared keys to be written to system logs. Individuals with read access to container logs or support archives can obtain these keys, leading to the potential compromise of encrypted network tunnels.&nbsp;</span>"
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38998"
                }
            ],
            "metrics": [
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV4_0": {
                        "attackVector": "LOCAL",
                        "attackComplexity": "LOW",
                        "attackRequirements": "NONE",
                        "privilegesRequired": "LOW",
                        "userInteraction": "NONE",
                        "vulnConfidentialityImpact": "HIGH",
                        "subConfidentialityImpact": "NONE",
                        "vulnIntegrityImpact": "HIGH",
                        "subIntegrityImpact": "NONE",
                        "vulnAvailabilityImpact": "NONE",
                        "subAvailabilityImpact": "NONE",
                        "exploitMaturity": "NOT_DEFINED",
                        "Safety": "NOT_DEFINED",
                        "Automatable": "NOT_DEFINED",
                        "Recovery": "NOT_DEFINED",
                        "valueDensity": "NOT_DEFINED",
                        "vulnerabilityResponseEffort": "NOT_DEFINED",
                        "providerUrgency": "NOT_DEFINED",
                        "version": "4.0",
                        "baseSeverity": "HIGH",
                        "baseScore": 8.4,
                        "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
                    }
                }
            ],
            "solutions": [
                {
                    "lang": "en",
                    "value": "Security update provided in Brocade SANnav 3.0.1a",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "<span>Security update provided in Brocade SANnav 3.0.1a</span>"
                        }
                    ]
                }
            ],
            "source": {
                "discovery": "UNKNOWN"
            },
            "x_generator": {
                "engine": "Vulnogram 1.0.5"
            }
        }
    }
}