---
id: CVE-2026-85423
title: >-
  A vulnerability has been identified in the data collection service of Brocade
  ASCG versions before 3.5.0
summary: >-
  A vulnerability has been identified in the data collection service of Brocade
  ASCG versions before 3.5.0. An API endpoint within the data collector service
  fails to perform authentication or authorization checks on incoming requests.
  An …
severity: high
cvss: 8.6
cvssVector: 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'
cvssSource: cna
cwe:
  - CWE-306
vendor: Brocade
product: Brocade Active Support Connectivity Gateway
affected:
  - active_support_connectivity_gateway < 3.5.0
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T06:25:40.444Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-85423'
references:
  - url: 'https://support.broadcom.com/external/content/SecurityAdvisories/0/38380'
tags:
  - cve.org
ingestedAt: '2026-10-08T07:18:54.848Z'
---

## Overview

A vulnerability has been identified in the data collection service of Brocade ASCG versions before 3.5.0. An API endpoint within the data collector service fails to perform authentication or authorization checks on incoming requests. An attacker with network access to the service can instruct the application to establish SSH connections to arbitrary hosts and execute arbitrary system commands, effectively turning the appliance into an unauthenticated proxy or execution vector.

## Affected

- `active_support_connectivity_gateway < 3.5.0`

## Remediation

Security update provided in Brocade ASCG 3.5.0
