Impact
An unauthenticated network attacker can query specific internal management endpoints on Brocade Active Support Connectivity Gateway before version 3.5.0 to enumerate configuration details and the state of managed Fabric OS switches. This results in the unintended disclosure of the SAN fabric management topology and switch connectivity attributes, compromising the confidentiality of network design and operational.
Affected Systems
The vulnerability affects Brocade ASCG, specifically the Active Support Connectivity Gateway product, in all releases earlier than 3.5.0. Endpoints that expose management information are the attack targets.
Risk and Exploitability
The listed CVSS score of 5.3 reflects a moderate severity. The EPSS score is not available and the vulnerability is not currently listed in the CISA KEV catalog. Attackers need only network access to the internal endpoints; no authentication is required. The combination of an unauthenticated network entry point and the moderate CVSS implies a realistic risk for organizations with exposed management interfaces, warranting timely remediation.
OpenCVE Enrichment