Description
An unauthenticated network-based attacker can query specific internal management endpoints on Brocade ASCG versions before 3.5.0 to enumerate the configuration details and state of managed Brocade Fabric OS (FOS) switches. This results in the unauthorized disclosure of the customer's SAN fabric management topology and switch connectivity attributes.
Published: 2026-10-08
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Disclosure of Management Topology
Action: Apply Patch
AI Analysis

Impact

An unauthenticated network attacker can query specific internal management endpoints on Brocade Active Support Connectivity Gateway before version 3.5.0 to enumerate configuration details and the state of managed Fabric OS switches. This results in the unintended disclosure of the SAN fabric management topology and switch connectivity attributes, compromising the confidentiality of network design and operational.

Affected Systems

The vulnerability affects Brocade ASCG, specifically the Active Support Connectivity Gateway product, in all releases earlier than 3.5.0. Endpoints that expose management information are the attack targets.

Risk and Exploitability

The listed CVSS score of 5.3 reflects a moderate severity. The EPSS score is not available and the vulnerability is not currently listed in the CISA KEV catalog. Attackers need only network access to the internal endpoints; no authentication is required. The combination of an unauthenticated network entry point and the moderate CVSS implies a realistic risk for organizations with exposed management interfaces, warranting timely remediation.

Generated by OpenCVE AI on October 8, 2026 at 08:21 UTC.

Remediation

Vendor Solution

Security update provided in Brocade ASCG 3.5.0


OpenCVE Recommended Actions

  • Install the security update to Brocade ASCG 3.5.0 as released by the vendor
  • Reconfigure or restrict access to the internal management endpoints so that only authorized users can query them; consider disabling the endpoints if not required
  • Continuously monitor network traffic for unexpected queries to the internal endpoints and enforce network segmentation to limit exposure

Generated by OpenCVE AI on October 8, 2026 at 08:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 08:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Disclosure of SAN Fabric Management Topology via Internal Endpoints

Thu, 08 Oct 2026 07:15:00 +0000

Type Values Removed Values Added
Description An unauthenticated network-based attacker can query specific internal management endpoints on Brocade ASCG versions before 3.5.0 to enumerate the configuration details and state of managed Brocade Fabric OS (FOS) switches. This results in the unauthorized disclosure of the customer's SAN fabric management topology and switch connectivity attributes.
Weaknesses CWE-200
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published:

Updated: 2026-10-08T06:54:22.995Z

Reserved: 2026-09-08T21:56:45.681Z

Link: CVE-2026-87426

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T07:16:33.270

Modified: 2026-10-08T07:16:33.270

Link: CVE-2026-87426

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T08:30:14Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor