---
cve: "CVE-2026-82372"
severity: "HIGH"
cvss: 8.5
epss: "0.2%"
vendor: "Brocade"
kev: false
exploited: false
published: "2026-09-24 19:08:43"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-10-05T03:13:14+02:00"
---

# CVE-2026-82372

> 8.5 HIGH

## Beschreibung

Improper handling of sensitive data during IPsec policy creation and modification in Brocade SANnav versions before 3.0.1a results in pre-shared keys being recorded in application logs. Individuals with read access to system log files or support bundles can view these credentials, leading to the potential exposure of keys used to secure network tunnels.

## CNA-Record (Kanon, cvelistV5)

- CNA: **brocade**
- State: PUBLISHED
- Stand: 2026-10-01 20:19:09
- CNA-CVSS: **8.5** (`CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N`)

## CISA-Anreicherung (vulnrichment/ADP)

- CISA-SSVC (Coordinator, v2.0.3):
  - Exploitation: **none**
  - Automatable: **no**
  - Technical Impact: **total**

## CVSS-Vektor

```
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Benachbart | warn |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |

## BSI-Hinweise (deutsch)

- [Broadcom Brocade SANnav: Mehrere Schwachstellen](https://wid.cert-bund.de/portal/wid/sicherheitshinweis/WID-SEC-W-2026-3528) — _BSI-Einstufung: hoch_
  Ein Angreifer kann mehrere Schwachstellen in Broadcom Brocade SANnav ausnutzen, um Administratorrechte zu erlangen, Sicherheitsmaßnahmen zu umgehen, beliebigen Code auszuführen, Daten zu manipulieren oder vertrauliche Informationen offenzulegen.

## Referenzen

- <https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38997>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-82372) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
