# CVE-2025-1053

## Summary

- **CVE ID:** CVE-2025-1053
- **Severity:** HIGH
- **CVSS Score:** 8.6 (CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N)
- **CWE:** CWE-532
- **Published:** Feb 14, 2025
- **Last Modified:** Mar 13, 2026

## Description

Under certain error conditions at time of SANnav installation or upgrade, the encryption key can be written into and obtained from a Brocade SANnav supportsave.  An attacker with privileged access to the Brocade SANnav database could use the encryption key to obtain passwords used by Brocade SANnav.

## Affected Products

- Brocade — Brocade SANnav (Brocade SANnav before 2.3.1b)

## References

- [CNA](https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25399)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.15%
- **EPSS Percentile:** 4.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._