CVE-2026-85423: High severity Brocade ASCG vulnerability
A vulnerability has been identified in the data collection service of Brocade ASCG versions before 3.5.0. An API endpoint within the data collector service fails to perform authentication or authorization checks on incoming requests. An attacker with network access to the service can instruct the application to establish SSH connections to arbitrary hosts and execute arbitrary system commands, effectively turning the appliance into an unauthenticated proxy or execution vector.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Brocade ASCGto a version that resolves this vulnerability.Fixed in 3.5.0
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Brocade ASCG versions before 3.5.0 are affected if an attacker has network access to the data collection service.
Does exploitation require credentials or user interaction?
No. The affected API endpoint does not perform authentication or authorization checks, and the CVSS vector indicates no privileges or user interaction are required.
What can an attacker do through the vulnerable endpoint?
An attacker can cause the appliance to establish SSH connections to arbitrary hosts and execute arbitrary system commands, potentially using it as an unauthenticated proxy or execution vector.
What version resolves the issue?
Upgrade Brocade ASCG to version 3.5.0 or later. Versions before 3.5.0 are identified as affected.