Description
An Improper Input Validation vulnerability for the registered case credentials in Brocade ASCG before v3.0 could allow a local authenticated user to provide invalid inputs like special characters leading to a Denial of Service (DoS) when collecting “supportsave” from a Brocade Switch.
Published: 2026-10-08
Score: 6.8 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

An Improper Input Validation flaw exists in the registered case credentials feature of Brocade Active Support Connectivity Gateway. A local authenticated user can submit inputs containing special characters that are not correctly filtered, causing the system to fail when it attempts to collect "supportsave" data from a Brocade Switch. The resulting crash or hang stops the support‑gathering process, denying the ability to retrieve diagnostic information and potentially disrupting management traffic, which is a classic DoS circumstance.

Affected Systems

The vulnerability affects Brocade ASCG devices running any version prior to 3.0. The security update that fixes the issue is available as Brocade ASCG 3.0. No specific minor revisions are listed, so any build older than 3.0 is considered susceptible.

Risk and Exploitability

The CVSS score of 6.8 indicates a moderate severity. EPSS information is not available and the vulnerability is not listed in the CISA KEV catalog. Because the flaw requires local authentication, an attacker must already have legitimate credentials or local access to the ASCG. An exploit would simply cause the supportsave operation to fail, resulting in a denial of service to the affected gateway and any dependent diagnostics.

Generated by OpenCVE AI on October 8, 2026 at 06:21 UTC.

Remediation

Vendor Solution

Security update provided in Brocade ASCG 3.0


OpenCVE Recommended Actions

  • Update the Brocade Active Support Connectivity Gateway to version 3.0 or later to apply the vendor‑provided fix.
  • Disable or restrict the use of the supportsave command until the firmware update is installed.
  • Monitor ASCG logs for abnormal input or service interruptions, and plan a replacement or upgrade if the device remains on an older release.

Generated by OpenCVE AI on October 8, 2026 at 06:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 06:45:00 +0000

Type Values Removed Values Added
Title Impaired Input Validation Causing Local Authenticated Denial of Service in Brocade ASCG

Thu, 08 Oct 2026 05:15:00 +0000

Type Values Removed Values Added
Description An Improper Input Validation vulnerability for the registered case credentials in Brocade ASCG before v3.0 could allow a local authenticated user to provide invalid inputs like special characters leading to a Denial of Service (DoS) when collecting “supportsave” from a Brocade Switch.
Weaknesses CWE-20
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published:

Updated: 2026-10-08T05:06:06.027Z

Reserved: 2023-10-19T01:33:10.047Z

Link: CVE-2023-5649

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T05:17:03.970

Modified: 2026-10-08T05:17:03.970

Link: CVE-2023-5649

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T06:30:17Z

Weaknesses
  • CWE-20

    Improper Input Validation