Database/Control plane, storage & DevOps
Brocade SANnav Management Portal web interface, before v2.3.0 and v2.2.2a: Remote unauthenticated users can bypass web
Impact
Remote unauthenticated users can bypass web authentication and authorization on the SANnav portal. That is the front door to the whole FC management estate - fabric inventory, zoning pushes, switch credentials, firmware distribution. Chained with the zone-management SQL injection above it turns a fully unauthenticated network position into control of tenant isolation across every managed fabric.
Who can reach it
Any host with network reachability to the SANnav web interface. No credentials at all.
What to do
Upgrade SANnav to 2.3.0 or 2.2.2a. Management-plane upgrade only - no fabric or array disruption. Because the pre-fix window allowed unauthenticated access, also rotate stored switch credentials and diff the live zonesets against your intended configuration rather than assuming the upgrade closes the incident.
References
Related entries
- OpenPMIx (PMIx library used by Slurm and Open MPI for job launch): A race in PMIx library code that executes with UID 0CVE-2023-41915 · OpenPMIx (PMIx library used by Slurm and Open MPI for job launch)High
- Ceph RADOS Gateway (RGW): RGW accepts a JWT whose header declares alg "none" and never checks the signature, so anyoneCVE-2024-48916 · Ceph RADOS Gateway (RGW)High
- HPE Insight Remote Support (Java deserialization): Java deserialization letting an unauthenticated attacker executeCVE-2024-53673 · HPE Insight Remote Support (Java deserialization)High
- PostgreSQL (libpq): Improper quoting in PQescape*CVE-2025-1094 · PostgreSQL (libpq)High
- HPE Performance Cluster Manager (HPCM) GUI authentication bypass: Authentication bypass in the HPCM web GUICVE-2025-27086 · HPE Performance Cluster Manager (HPCM) GUI authentication bypassHigh
- HTCondor (IDToken authorization restrictions): The per-token authorization restrictions attached withCVE-2025-30093 · HTCondor (IDToken authorization restrictions)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.