Description
An authentication flaw exists in the Brocade ASCG administrative management service component. An unauthenticated network user can issue direct API requests to perform privileged actions, including accessing sensitive system configuration mapping data, modifying managed device inventories, and altering operational settings. This vulnerability affects all versions of Brocade ASCG before 3.5.0.
Published: 2026-10-08
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Unauthorized Access and Configuration Manipulation
Action: Immediate Patch
AI Analysis

Impact

An authentication flaw in the Brocade Active Support Connectivity Gateway administrative service allows an unauthenticated network user to issue API requests that perform privileged actions. These actions include reading sensitive system configuration mapping data, modifying managed device inventories, and altering operational settings. This missing authentication weakness (CWE‑306) enables an attacker to configure and potentially disrupt network operations or retrieve confidential configuration information.

Affected Systems

The vulnerability affects all versions of Brocade Active Support Connectivity Gateway (ASCG) prior to version 3.5.0. The flaw resides in the administrative management service component that runs on the ASCG appliance.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity, and because the EPSS score is not available the exploitation probability is unknown but potentially significant. The vulnerability is not listed in the CISA KEV catalog. The attack vector is likely over a network connection; any remote entity can send unauthenticated API requests to the ASCG management interface and execute the privileged operations disclosed.

Generated by OpenCVE AI on October 8, 2026 at 07:21 UTC.

Remediation

Vendor Solution

Security update provided in Brocade ASCG 3.5.0


OpenCVE Recommended Actions

  • Apply the Brocade ASCG 3.5.0 or later security update to eliminate the authentication flaw.
  • Restrict network access to the ASCG administrative interface, for example by configuring firewall rules or VLAN segmentation to limit exposure to trusted administrators.
  • Validate that API endpoints enforce authentication and review permission settings to ensure only authorized users can invoke privileged actions.

Generated by OpenCVE AI on October 8, 2026 at 07:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated API Access Allows Privileged Configuration Changes in Brocade ASCG

Thu, 08 Oct 2026 06:45:00 +0000

Type Values Removed Values Added
Description An authentication flaw exists in the Brocade ASCG administrative management service component. An unauthenticated network user can issue direct API requests to perform privileged actions, including accessing sensitive system configuration mapping data, modifying managed device inventories, and altering operational settings. This vulnerability affects all versions of Brocade ASCG before 3.5.0.
Weaknesses CWE-306
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published:

Updated: 2026-10-08T06:39:59.090Z

Reserved: 2026-09-03T21:31:03.838Z

Link: CVE-2026-85489

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T07:16:32.727

Modified: 2026-10-08T07:16:32.727

Link: CVE-2026-85489

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T07:30:13Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function