Impact
An authentication flaw in the Brocade Active Support Connectivity Gateway administrative service allows an unauthenticated network user to issue API requests that perform privileged actions. These actions include reading sensitive system configuration mapping data, modifying managed device inventories, and altering operational settings. This missing authentication weakness (CWE‑306) enables an attacker to configure and potentially disrupt network operations or retrieve confidential configuration information.
Affected Systems
The vulnerability affects all versions of Brocade Active Support Connectivity Gateway (ASCG) prior to version 3.5.0. The flaw resides in the administrative management service component that runs on the ASCG appliance.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, and because the EPSS score is not available the exploitation probability is unknown but potentially significant. The vulnerability is not listed in the CISA KEV catalog. The attack vector is likely over a network connection; any remote entity can send unauthenticated API requests to the ASCG management interface and execute the privileged operations disclosed.
OpenCVE Enrichment