CVE-2026-85423High· 8.6▾ TwilightA vulnerability has been identified in the data collection service of Brocade ASCG versions before 3.5.0. An API endpoint within the data collector service fails to perform authentication or authorization checks on incoming requests. An …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 47.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A vulnerability has been identified in the data collection service of Brocade ASCG versions before 3.5.0. An API endpoint within the data collector service fails to perform authentication or authorization checks on incoming requests. An attacker with network access to the service can instruct the application to establish SSH connections to arbitrary hosts and execute arbitrary system commands, effectively turning the appliance into an unauthenticated proxy or execution vector.
active_support_connectivity_gateway < 3.5.0Security update provided in Brocade ASCG 3.5.0
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-85421High· 8.7A critical security vulnerability has been identified in Brocade ASCG versions before 3.5.0
CVE-2026-85489High· 8.7An authentication flaw exists in the Brocade ASCG administrative management service component
CVE-2026-85486High· 8.6Brocade ASCG before 3.5.0 improperly processes user input by evaluating form data prior to validation
CVE-2026-85488High· 7.0Brocade ASCG before 3.5.0 has a well-known Brocade default password embedded in a script distributed to every customer
CVE-2026-85487High· 8.6A path traversal vulnerability exists in the HTTP service component of Brocade ASCG versions before 3.5.0
CVE-2026-85422High· 8.4A vulnerability in Brocade ASCG version before 3.5.0 could allow an attacker to obtain a static cryptographic key hardcoded into the software binaries to secure sensitive data at rest and to protect inter-node communication protocols