Impact
The HTTPS service in Brocade Active Support Connectivity Gateway fails to enforce authentication or access control checks on incoming requests. An unauthenticated attacker with network access can issue control commands, alter cluster states, and modify system configurations, which effectively allows a complete compromise of the streaming service control plane. This is a critical weakness that can lead to full system takeover.
Affected Systems
Brocade ASCG, all versions prior to 3.5.0 are affected. The vulnerability applies to the HTTPS management interface of the Brocade Active Support Connectivity Gateway product supplied by Brocade.
Risk and Exploitability
The vulnerability has a high CVSS score of 8.7. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires remote network access to the HTTPS port; no authentication is required, and an attacker only needs to send crafted requests to the service. Once authenticated, the attacker can execute arbitrary control commands and alter configurations to achieve full control of the system.
OpenCVE Enrichment