VulnSea

active_support_connectivity_gateway vulnerabilities

CVEs whose affected-version data names the active_support_connectivity_gateway package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

10 CVEsRSS

CVE-2026-85423High· 8.6
today

A vulnerability has been identified in the data collection service of Brocade ASCG versions before 3.5.0

A vulnerability has been identified in the data collection service of Brocade ASCG versions before 3.5.0. An API endpoint within the data collector service fails to perform authentication or authorization checks on incoming requests. An …

▾ TwilightBrocade · Brocade Active Support Connectivity Gatewayvia CVEORG
CVE-2026-85486High· 8.6
today

Brocade ASCG before 3.5.0 improperly processes user input by evaluating form data prior to validation

Brocade ASCG before 3.5.0 improperly processes user input by evaluating form data prior to validation. When an authenticated user submits a configuration form, the submitted text could immediately be processed. A malicious actor with bas…

▾ TwilightBrocade · Brocade Active Support Connectivity Gatewayvia CVEORG
CVE-2026-85421High· 8.7
today

A critical security vulnerability has been identified in Brocade ASCG versions before 3.5.0

A critical security vulnerability has been identified in Brocade ASCG versions before 3.5.0. The HTTPS service fails to properly enforce authentication or access control checks on incoming requests. An unauthenticated attacker with netwo…

▾ TwilightBrocade · Brocade Active Support Connectivity Gatewayvia CVEORG
CVE-2026-85488High· 7.0
today

Brocade ASCG before 3.5.0 has a well-known Brocade default password embedded in a script distributed to every customer

Brocade ASCG before 3.5.0 has a well-known Brocade default password embedded in a script distributed to every customer. Any local authenticated user with read access to the installation path can discover this credential and perform privi…

▾ TwilightBrocade · Brocade Active Support Connectivity Gatewayvia CVEORG
CVE-2026-85487High· 8.6
today

A path traversal vulnerability exists in the HTTP service component of Brocade ASCG versions before 3.5.0

A path traversal vulnerability exists in the HTTP service component of Brocade ASCG versions before 3.5.0. An unauthenticated attacker on the local network could send a manipulated API request to the service endpoint bypassing path restr…

▾ TwilightBrocade · Brocade Active Support Connectivity Gatewayvia CVEORG
CVE-2026-85422High· 8.4
today

A vulnerability in Brocade ASCG version before 3.5.0 could allow an attacker to obtain a static cryptographic key hardcoded into the software binaries to secure sensitive data at rest and to protect inter-node communication protocols

A vulnerability in Brocade ASCG version before 3.5.0 could allow an attacker to obtain a static cryptographic key hardcoded into the software binaries to secure sensitive data at rest and to protect inter-node communication protocols. An…

▾ TwilightBrocade · Brocade Active Support Connectivity Gatewayvia CVEORG
CVE-2026-85489High· 8.7
today

An authentication flaw exists in the Brocade ASCG administrative management service component

An authentication flaw exists in the Brocade ASCG administrative management service component. An unauthenticated network user can issue direct API requests to perform privileged actions, including accessing sensitive system configuratio…

▾ TwilightBrocade · Brocade Active Support Connectivity Gatewayvia CVEORG
CVE-2026-85490High· 7.7
today

When Brocade ASCG before 3.5.0 processes support bundle archives ingested from remote compromised endpoints, the application fails to sanitize path traversal sequences contained within archive entries prior to extraction

When Brocade ASCG before 3.5.0 processes support bundle archives ingested from remote compromised endpoints, the application fails to sanitize path traversal sequences contained within archive entries prior to extraction. An unauthentica…

▾ TwilightBrocade · Brocade Active Support Connectivity Gatewayvia CVEORG
CVE-2023-5649Medium· 6.8
today

An Improper Input Validation vulnerability for the registered case credentials in Brocade ASCG before v3.0 could allow a local authenticated user to provide invalid inputs like special characters leading to a Denial of Service (DoS) when…

An Improper Input Validation vulnerability for the registered case credentials in Brocade ASCG before v3.0 could allow a local authenticated user to provide invalid inputs like special characters leading to a Denial of Service (DoS) when…

▾ SunlitBrocade · Brocade Active Support Connectivity Gatewayvia NVD
CVE-2023-5648Medium· 6.5
today

In Brocade ASCG before Brocade ASCG v3.0, several security-related HTTP Headers were missing in various Brocade ASCG URL paths, aiding unauthenticated attackers to perform attacks such as Cross-Site Scripting, Clickjacking, Information d…

In Brocade ASCG before Brocade ASCG v3.0, several security-related HTTP Headers were missing in various Brocade ASCG URL paths, aiding unauthenticated attackers to perform attacks such as Cross-Site Scripting, Clickjacking, Information d…

▾ SunlitBrocade · Active Support Connectivity Gatewayvia NVD
active_support_connectivity_gateway vulnerabilities (CVEs) · VulnSea