Impact
An unauthenticated attacker can inject an unauthorized Certificate Authority certificate into the TLS client trust store of Brocade Active Support Connectivity Gateway before version 3.5.0. This alteration makes the gateway trust certificates it should not, allowing the attacker to intercept or alter outbound traffic to managed switches and peer nodes. The vulnerability is a direct flaw in certificate validation (CWE‑295) and permits manipulation of cryptographic trust mechanisms.
Affected Systems
The affected product is Brocade Active Support Connectivity Gateway. All running versions prior to 3.5.0 are vulnerable; no specific sub‑versions are listed.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity impact, but the EPSS score is currently unavailable, implying no known exploitation data. The vulnerability is not listed in CISA KEV, suggesting it is not a widely known exploited flaw yet. The attack requires no authentication to the management interface and can be performed over an unauthenticated network session, so the attack vector is likely remote via the exposed management port. This makes mitigation urgent for any reachable instance.
OpenCVE Enrichment