CVE-2026-87425: High severity vulnerability
An unauthenticated remote attacker can modify the TLS client trust store in Brocade ASCG versions before 3.5.0. By supplying an unauthorized Certificate Authority (CA) certificate to an unauthenticated management interface, the attacker can cause the system to trust unauthorized certificates, potentially enabling Man-in-the-Middle (MITM) attacks against outbound communications with managed switches and peer nodes.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Brocade ASCGto a version that resolves this vulnerability.Fixed in 3.5.0
Event History
Frequently Asked Questions
Which deployments are affected?
Brocade ASCG versions before 3.5.0 are affected.
Does exploitation require an account or user interaction?
No. The issue is exploitable by an unauthenticated remote attacker through an unauthenticated management interface.
What is the likely security impact after exploitation?
An attacker can add an unauthorized CA certificate to the TLS client trust store. This can make unauthorized certificates trusted and may enable MITM attacks on outbound communications to managed switches and peer nodes.