Impact
The vulnerability exists in Brocade ASCG versions prior to 3.5.0 and permits an attacker to extract a static cryptographic key that is hardcoded in the firmware. This key is used to protect data at rest and inter‑node communication, so once it is obtained, the attacker can decrypt stored management credentials or create forged administrative synchronization messages. The consequence is loss of confidentiality for sensitive data and the ability to subvert authentication mechanisms, effectively compromising system integrity.
Affected Systems
The affected products are Brocade Active Support Connectivity Gateway devices running any software version earlier than 3.5.0. No specific revisions are listed; all builds before the 3.5.0 release are vulnerable. The vendor, Brocade (Broadcom), publishes the issue for all ASCG deployments running the older firmware.
Risk and Exploitability
The CVSS score of 8.4 indicates a high severity vulnerability. The EPSS score is not available, so the current exploitation probability is unknown, but the lack of a KEV listing does not diminish the risk because the key extraction can be carried out with tools that do not require an expanded attack surface. A likely attack vector would be a privileged user or an attacker who has remote access to the management interface, potentially leveraging cross‑site scripting or command injection that can read the binary. The impact remains high, and if the vulnerability is exploited, it could lead to credential theft and unauthorized control of the ASCG cluster.
OpenCVE Enrichment