CVE-2023-5649: Input Validation
An Improper Input Validation vulnerability for the registered case credentials in Brocade ASCG before v3.0 could allow a local authenticated user to provide invalid inputs like special characters leading to a Denial of Service (DoS) when collecting “supportsave” from a Brocade Switch.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Brocade ASCGto a version that resolves this vulnerability.Fixed in 3.0
Event History
Frequently Asked Questions
Who can exploit this issue?
Exploitation requires local authenticated access. The issue affects Brocade ASCG before version 3.0 when handling registered case credentials during supportsave collection from a Brocade Switch.
What is the likely impact of successful exploitation?
A local authenticated user can supply invalid input, such as special characters, and cause a denial of service while collecting supportsave data from a Brocade Switch.
What should be prioritized for remediation?
Upgrade Brocade ASCG to version 3.0 or later. Until then, restrict local authenticated access and avoid using special characters or other invalid values in registered case credentials during supportsave collection.