Description
A vulnerability has been identified in the data collection service of Brocade ASCG versions before 3.5.0. An API endpoint within the data collector service fails to perform authentication or authorization checks on incoming requests. An attacker with network access to the service can instruct the application to establish SSH connections to arbitrary hosts and execute arbitrary system commands, effectively turning the appliance into an unauthenticated proxy or execution vector.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Security update provided in Brocade ASCG 3.5.0
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 08 Oct 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been identified in the data collection service of Brocade ASCG versions before 3.5.0. An API endpoint within the data collector service fails to perform authentication or authorization checks on incoming requests. An attacker with network access to the service can instruct the application to establish SSH connections to arbitrary hosts and execute arbitrary system commands, effectively turning the appliance into an unauthenticated proxy or execution vector. | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: brocade
Published:
Updated: 2026-10-08T06:25:40.444Z
Reserved: 2026-09-03T19:44:37.306Z
Link: CVE-2026-85423
No data.
Status : Received
Published: 2026-10-08T07:16:32.177
Modified: 2026-10-08T07:16:32.177
Link: CVE-2026-85423
No data.
OpenCVE Enrichment
No data.
Weaknesses