Impact
A path traversal flaw in the HTTP service of Brocade ASCG allows an attacker who can reach the device on the local network to craft API requests that bypass path restrictions. This vulnerability enables the reading, writing, or deletion of arbitrary files on the system, potentially leading to compromise of system configurations, sensitive data leakage, or disruption of the gateway’s operation. The weakness is a classic directory traversal problem as defined by CWE-22.
Affected Systems
The issue affects Brocade Active Support Connectivity Gateway devices running any ASCG version prior to 3.5.0. All installations of these products that expose the HTTP API to local network traffic are vulnerable.
Risk and Exploitability
With a CVSS score of 8.6, this vulnerability is considered high risk. Although no EPSS score is available and it is not listed in the CISA KEV catalog, the local-network access requirement means that attackers who can connect to the device can easily exploit the flaw. The exploitation path involves sending a crafted HTTP request to the vulnerable endpoint; no authentication is required, and the attack can be performed from any host within the same local network segment.
OpenCVE Enrichment