Description
When Brocade ASCG before 3.5.0 processes support bundle archives ingested from remote compromised endpoints, the application fails to sanitize path traversal sequences contained within archive entries prior to extraction. An unauthenticated remote attacker capable of sending or intercepting ingested archive files can leverage this flaw to write arbitrary files to restricted locations on the underlying host, potentially leading to remote code execution.
Published: 2026-10-08
Score: 7.7 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from improper sanitization of file paths contained within support bundle archives processed by Brocade Active Support Connectivity Gateway (ASCG) releases before version 3.5.0. Because the application does not neutralize path traversal sequences in archive entries before extracting them, an attacker could inject archive files that contain files referencing privileged filesystem locations. This flaw allows the injection of files that overwrite system or program files, leading to potential remote code execution. The weakness is a classic path traversal flaw, corresponding to CWE‑22.

Affected Systems

Brocade Active Support Connectivity Gateway (ASCG) products deployed before the 3.5.0 release are affected. No later releases, notably 3.5.0 and above, contain the fix.

Risk and Exploitability

The CVSS score of 7.7 indicates a high severity. Because the flaw is exploitable by an unauthenticated remote user who can send or intercept archive files that the gateway ingests, the risk is significant. EPSS data is not available, and the issue is not listed in CISA’s KEV catalog, but the combination of high CVSS and the remote, unauthenticated nature of the attack vector suggests that the vulnerability could be abused in targeted or opportunistic attacks.

Generated by OpenCVE AI on October 8, 2026 at 07:20 UTC.

Remediation

Vendor Solution

Security update provided in Brocade ASCG 3.5.0


OpenCVE Recommended Actions

  • Apply the security update to Brocade ASCG version 3.5.0 or later, which corrects the path validation bug.
  • Restrict the ingestion of support bundle archives to authenticated, trusted sources only or quarantine unvalidated archives before processing.
  • If upgrading immediately is not possible, place the device behind a firewall or network segmentation that blocks direct connections from untrusted ends, and monitor for attempts to deliver archives with suspicious path components.

Generated by OpenCVE AI on October 8, 2026 at 07:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Title ASCG Path Traversal Enables Remote Code Execution

Thu, 08 Oct 2026 06:45:00 +0000

Type Values Removed Values Added
Description When Brocade ASCG before 3.5.0 processes support bundle archives ingested from remote compromised endpoints, the application fails to sanitize path traversal sequences contained within archive entries prior to extraction. An unauthenticated remote attacker capable of sending or intercepting ingested archive files can leverage this flaw to write arbitrary files to restricted locations on the underlying host, potentially leading to remote code execution.
Weaknesses CWE-22
References
Metrics cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published:

Updated: 2026-10-08T06:42:43.052Z

Reserved: 2026-09-03T21:31:03.838Z

Link: CVE-2026-85490

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T07:16:32.860

Modified: 2026-10-08T07:16:32.860

Link: CVE-2026-85490

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T07:30:13Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')