A vulnerability has been identified in the data collection service of Brocade ASCG versions before 3.5.0. An API endpoint within the data collector service fails to perform authentication or authorization checks on incoming requests. An attacker with network access to the service can instruct the application to establish SSH connections to arbitrary hosts and execute arbitrary system commands, effectively turning the appliance into an unauthenticated proxy or execution vector.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Security update provided in Brocade ASCG 3.5.0
Workaround
No workaround given by the vendor.
References
History
Thu, 08 Oct 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been identified in the data collection service of Brocade ASCG versions before 3.5.0. An API endpoint within the data collector service fails to perform authentication or authorization checks on incoming requests. An attacker with network access to the service can instruct the application to establish SSH connections to arbitrary hosts and execute arbitrary system commands, effectively turning the appliance into an unauthenticated proxy or execution vector. | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: brocade
Published:
Updated: 2026-10-08T06:25:40.444Z
Reserved: 2026-09-03T19:44:37.306Z
Link: CVE-2026-85423
No data.
Status : Received
Published: 2026-10-08T07:16:32.177
Modified: 2026-10-08T07:16:32.177
Link: CVE-2026-85423
No data.
OpenCVE Enrichment
No data.
Weaknesses