CVE-2026-85489
Received Received - Intake

Authentication Bypass in Brocade ASCG Admin Service

Vulnerability report for CVE-2026-85489, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: Brocade Communications Systems, LLC

Description

An authentication flaw exists in the Brocade ASCG administrative management service component. An unauthenticated network user can issue direct API requests to perform privileged actions, including accessing sensitive system configuration mapping data, modifying managed device inventories, and altering operational settings. This vulnerability affects all versions of Brocade ASCG before 3.5.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Brocade Brocade Active Support Connectivity Gateway 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authentication flaw in the Brocade ASCG administrative management service. An unauthenticated attacker can send direct API requests to perform privileged actions like accessing sensitive system configuration data, modifying device inventories, or changing operational settings. It affects all versions of Brocade ASCG before 3.5.0.

Detection Guidance

Since this is an authentication flaw in Brocade ASCG before version 3.5.0, detection involves checking for unauthorized API requests or privileged actions. Monitor network traffic for API calls to the ASCG service on affected ports. Check system logs for unusual administrative actions or configuration changes. Verify ASCG version to confirm if the system is vulnerable.

Impact Analysis

An attacker could exploit this to access sensitive system data, alter device configurations, or disrupt operations. This could lead to unauthorized changes, data breaches, or service disruptions in systems managed by Brocade ASCG.

Compliance Impact

This vulnerability could lead to unauthorized access or modification of sensitive data, potentially violating GDPR (data protection) or HIPAA (health data privacy) requirements. Compliance may be compromised if systems are not patched.

Mitigation Strategies

Immediately upgrade Brocade ASCG to version 3.5.0 or later to address the authentication flaw. Restrict network access to the ASCG administrative management service API endpoints to trusted sources only. Review system logs for unauthorized API requests or privileged actions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85489. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart