CVE-2026-87428: High severity vulnerability
In Brocade ASCG before 3.5.0, a local unauthorized user on the ASCG VM who can issue a request to the SANnav host network namespace can extract stored management credentials for onboarded SANnav instances and compromise connected Brocade SANnav servers or managed Brocade Fibre Channel switches.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Brocade ASCGto a version that resolves this vulnerability.Fixed in 3.5.0
Event History
Frequently Asked Questions
Which environments are exposed to this issue?
Brocade ASCG deployments before 3.5.0 are affected when a local unauthorized user on the ASCG virtual machine can issue requests to the SANnav host network namespace. The impact can extend to onboarded SANnav instances, connected Brocade SANnav servers, and managed Brocade Fibre Channel switches.
What access does an attacker need?
The attacker needs local access as an unauthorized user on the ASCG VM and the ability to issue a request to the SANnav host network namespace. No user interaction is required.
What can an attacker obtain and compromise?
An attacker can extract stored management credentials for onboarded SANnav instances. Those credentials can then be used to compromise connected Brocade SANnav servers or managed Brocade Fibre Channel switches.
How can I determine whether my deployment is affected?
Verify whether ASCG is running a version before 3.5.0. Also assess whether local unauthorized users on the ASCG VM can issue requests to the SANnav host network namespace and whether the deployment stores management credentials for onboarded SANnav instances.