Description
A vulnerability in Brocade ASCG version before 3.5.0 could allow an attacker to obtain a static cryptographic key hardcoded into the software binaries to secure sensitive data at rest and to protect inter-node communication protocols. An attacker who extracts this key can decrypt stored management credentials or craft forged administrative synchronization messages.
Published: 2026-10-08
Score: 8.4 High
EPSS: n/a
KEV: No
Impact: Information Disclosure and Credential Theft
Action: Immediate Patch
AI Analysis

Impact

The vulnerability exists in Brocade ASCG versions prior to 3.5.0 and permits an attacker to extract a static cryptographic key that is hardcoded in the firmware. This key is used to protect data at rest and inter‑node communication, so once it is obtained, the attacker can decrypt stored management credentials or create forged administrative synchronization messages. The consequence is loss of confidentiality for sensitive data and the ability to subvert authentication mechanisms, effectively compromising system integrity.

Affected Systems

The affected products are Brocade Active Support Connectivity Gateway devices running any software version earlier than 3.5.0. No specific revisions are listed; all builds before the 3.5.0 release are vulnerable. The vendor, Brocade (Broadcom), publishes the issue for all ASCG deployments running the older firmware.

Risk and Exploitability

The CVSS score of 8.4 indicates a high severity vulnerability. The EPSS score is not available, so the current exploitation probability is unknown, but the lack of a KEV listing does not diminish the risk because the key extraction can be carried out with tools that do not require an expanded attack surface. A likely attack vector would be a privileged user or an attacker who has remote access to the management interface, potentially leveraging cross‑site scripting or command injection that can read the binary. The impact remains high, and if the vulnerability is exploited, it could lead to credential theft and unauthorized control of the ASCG cluster.

Generated by OpenCVE AI on October 8, 2026 at 07:25 UTC.

Remediation

Vendor Solution

Security update provided in Brocade ASCG 3.5.0


OpenCVE Recommended Actions

  • Apply the security update to Brocade ASCG 3.5.0 or later
  • If patching is not immediately possible, isolate the affected ASCG devices from untrusted networks and disable external management interfaces
  • Monitor for abnormal administrative synchronization traffic and audit decryption logs to detect potential key compromise

Generated by OpenCVE AI on October 8, 2026 at 07:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Title Brocade ASCG Hardcoded Cryptographic Key Disclosure Vulnerability

Thu, 08 Oct 2026 06:45:00 +0000

Type Values Removed Values Added
Description A vulnerability in Brocade ASCG version before 3.5.0 could allow an attacker to obtain a static cryptographic key hardcoded into the software binaries to secure sensitive data at rest and to protect inter-node communication protocols. An attacker who extracts this key can decrypt stored management credentials or craft forged administrative synchronization messages.
Weaknesses CWE-798
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published:

Updated: 2026-10-08T06:20:40.678Z

Reserved: 2026-09-03T19:44:37.306Z

Link: CVE-2026-85422

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T07:16:32.033

Modified: 2026-10-08T07:16:32.033

Link: CVE-2026-85422

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T07:30:13Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials