CVE-2026-85421: High severity Brocade ASCG vulnerability
A critical security vulnerability has been identified in Brocade ASCG versions before 3.5.0. The HTTPS service fails to properly enforce authentication or access control checks on incoming requests. An unauthenticated attacker with network access can issue control commands, alter cluster states, and modify system configurations, leading to a complete compromise of the streaming service control plane.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Brocade ASCGto a version that resolves this vulnerability.Fixed in 3.5.0
Event History
Frequently Asked Questions
Which deployments are affected?
Brocade ASCG versions before 3.5.0 are affected. Exposure requires network reachability to the ASCG HTTPS service.
What does an attacker need to exploit this issue?
An attacker needs only network access to the HTTPS service. No authentication, privileges, or user interaction are required.
What could an attacker do after exploitation?
An unauthenticated attacker can issue control commands, alter cluster states, and modify system configurations. This can result in complete compromise of the streaming service control plane.
What is the available remediation?
Upgrade Brocade ASCG to version 3.5.0 or later. The issue affects versions before 3.5.0.