Impact
An Improper Input Validation flaw exists in the registered case credentials feature of Brocade Active Support Connectivity Gateway. A local authenticated user can submit inputs containing special characters that are not correctly filtered, causing the system to fail when it attempts to collect "supportsave" data from a Brocade Switch. The resulting crash or hang stops the support‑gathering process, denying the ability to retrieve diagnostic information and potentially disrupting management traffic, which is a classic DoS circumstance.
Affected Systems
The vulnerability affects Brocade ASCG devices running any version prior to 3.0. The security update that fixes the issue is available as Brocade ASCG 3.0. No specific minor revisions are listed, so any build older than 3.0 is considered susceptible.
Risk and Exploitability
The CVSS score of 6.8 indicates a moderate severity. EPSS information is not available and the vulnerability is not listed in the CISA KEV catalog. Because the flaw requires local authentication, an attacker must already have legitimate credentials or local access to the ASCG. An exploit would simply cause the supportsave operation to fail, resulting in a denial of service to the affected gateway and any dependent diagnostics.
OpenCVE Enrichment