Description
A path traversal vulnerability exists in the HTTP service component of Brocade ASCG versions before 3.5.0. An unauthenticated attacker on the local network could send a manipulated API request to the service endpoint bypassing path restrictions to arbitrary file read, file write, or file deletion operations.
Published: 2026-10-08
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: Remote File Access via Path Traversal
Action: Immediate Patch
AI Analysis

Impact

A path traversal flaw in the HTTP service of Brocade ASCG allows an attacker who can reach the device on the local network to craft API requests that bypass path restrictions. This vulnerability enables the reading, writing, or deletion of arbitrary files on the system, potentially leading to compromise of system configurations, sensitive data leakage, or disruption of the gateway’s operation. The weakness is a classic directory traversal problem as defined by CWE-22.

Affected Systems

The issue affects Brocade Active Support Connectivity Gateway devices running any ASCG version prior to 3.5.0. All installations of these products that expose the HTTP API to local network traffic are vulnerable.

Risk and Exploitability

With a CVSS score of 8.6, this vulnerability is considered high risk. Although no EPSS score is available and it is not listed in the CISA KEV catalog, the local-network access requirement means that attackers who can connect to the device can easily exploit the flaw. The exploitation path involves sending a crafted HTTP request to the vulnerable endpoint; no authentication is required, and the attack can be performed from any host within the same local network segment.

Generated by OpenCVE AI on October 8, 2026 at 07:22 UTC.

Remediation

Vendor Solution

Security update provided in Brocade ASCG 3.5.0


OpenCVE Recommended Actions

  • Apply the Brocade ASCG 3.5.0 security update or later to eliminate the path traversal flaw.
  • Restrict local network access to the ASCG HTTP service using firewall rules or network segmentation so that only trusted hosts can reach the vulnerable endpoint until the update is applied.
  • Monitor device logs for anomalous file access or unexpected HTTP API traffic that may indicate exploitation attempts before the patch is deployed.

Generated by OpenCVE AI on October 8, 2026 at 07:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Local Path Traversal in Brocade ASCG HTTP API

Thu, 08 Oct 2026 06:45:00 +0000

Type Values Removed Values Added
Description A path traversal vulnerability exists in the HTTP service component of Brocade ASCG versions before 3.5.0. An unauthenticated attacker on the local network could send a manipulated API request to the service endpoint bypassing path restrictions to arbitrary file read, file write, or file deletion operations.
Weaknesses CWE-22
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published:

Updated: 2026-10-08T06:32:03.915Z

Reserved: 2026-09-03T21:31:03.838Z

Link: CVE-2026-85487

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T07:16:32.450

Modified: 2026-10-08T07:16:32.450

Link: CVE-2026-85487

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T07:30:13Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')