CVE-2026-85488
Received Received - Intake

Default Password in Brocade ASCG Leading to Privilege Escalation

Vulnerability report for CVE-2026-85488, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: Brocade Communications Systems, LLC

Description

Brocade ASCG before 3.5.0 has a well-known Brocade default password embedded in a script distributed to every customer. Any local authenticated user with read access to the installation path can discover this credential and perform privilege escalation on affected Open Virtual Appliance (OVA) deployments, where default configuration settings remain in place.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Brocade Brocade Active Support Connectivity Gateway 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-798 The product contains hard-coded credentials, such as a password or cryptographic key.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Brocade ASCG before version 3.5.0 contains a hardcoded default password in a script provided to customers. Local authenticated users with read access to the installation path can find this password and use it to escalate privileges. This affects Open Virtual Appliance deployments where default settings are unchanged.

Detection Guidance

Check for the presence of Brocade ASCG versions before 3.5.0 by inspecting installed scripts or configuration files in the default installation path. Look for embedded default credentials in readable files.

Impact Analysis

An attacker with local access could exploit this to gain elevated privileges on the system. This could allow unauthorized control over the Brocade ASCG, potentially leading to data breaches or further network compromise.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. Organizations may face compliance violations, legal penalties, and reputational damage if exploited.

Mitigation Strategies

Upgrade Brocade ASCG to version 3.5.0 or later to remove the default embedded password. Ensure default configuration settings are changed to prevent privilege escalation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85488. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart