CVE-2023-5649
Received Received - Intake

Improper Input Validation in Brocade ASCG Leads to DoS

Vulnerability report for CVE-2023-5649, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: Brocade Communications Systems, LLC

Description

An Improper Input Validation vulnerability for the registered case credentials in Brocade ASCG before v3.0 could allow a local authenticated user to provide invalid inputs like special characters leading to a Denial of Service (DoS) when collecting β€œsupportsave” from a Brocade Switch.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Brocade Brocade Active Support Connectivity Gateway 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Improper Input Validation issue in Brocade ASCG before version 3.0. A local authenticated user can exploit it by providing invalid inputs like special characters. This leads to a Denial of Service (DoS) when collecting 'supportsave' from a Brocade Switch.

Detection Guidance

This vulnerability affects Brocade ASCG before v3.0 and involves improper input validation leading to DoS. Detection requires checking the ASCG version and monitoring for unusual activity during supportsave collection. No specific commands are provided in the context.

Impact Analysis

The vulnerability allows a local authenticated attacker to cause a Denial of Service by crashing the supportsave collection process on a Brocade Switch. This disrupts normal operations and may require system recovery.

Compliance Impact

This vulnerability does not directly impact compliance with GDPR or HIPAA as it involves a local authenticated user causing a Denial of Service (DoS) on a Brocade Switch by providing invalid inputs. There is no evidence of data exposure or unauthorized access that would typically affect these regulations.

Mitigation Strategies

Update Brocade ASCG to version 3.0 or later to address the improper input validation issue. Ensure only valid inputs are accepted during supportsave collection to prevent DoS conditions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2023-5649. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart