CVE-2026-87425
Received Received - Intake

TLS Client Trust Store Modification in Brocade ASCG

Vulnerability report for CVE-2026-87425, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: Brocade Communications Systems, LLC

Description

An unauthenticated remote attacker can modify the TLS client trust store in Brocade ASCG versions before 3.5.0. By supplying an unauthorized Certificate Authority (CA) certificate to an unauthenticated management interface, the attacker can cause the system to trust unauthorized certificates, potentially enabling Man-in-the-Middle (MITM) attacks against outbound communications with managed switches and peer nodes.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Brocade Brocade Active Support Connectivity Gateway 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-295 The product does not validate, or incorrectly validates, a certificate.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an unauthenticated remote attacker to modify the TLS client trust store in Brocade ASCG versions before 3.5.0. By providing an unauthorized Certificate Authority (CA) certificate to the unauthenticated management interface, the attacker can make the system trust unauthorized certificates. This could enable Man-in-the-Middle (MITM) attacks on outbound communications with managed switches and peer nodes.

Detection Guidance

To detect this vulnerability, check the Brocade ASCG version on your system. If it is before 3.5.0, the system is vulnerable. Verify the TLS client trust store for unauthorized CA certificates by inspecting the management interface and outbound communications for unexpected certificate authorities.

Impact Analysis

An attacker could intercept, modify, or eavesdrop on sensitive communications between the Brocade ASCG and managed switches or peer nodes. This may lead to data breaches, unauthorized access to network traffic, or manipulation of network operations without detection.

Compliance Impact

This vulnerability could violate compliance requirements by enabling unauthorized access to sensitive data in transit, such as personal or health information. Organizations may fail to meet GDPR's data protection principles or HIPAA's security requirements for encrypted communications.

Mitigation Strategies

Upgrade Brocade ASCG to version 3.5.0 or later to address the trust store modification issue. Ensure the management interface is not exposed to untrusted networks and restrict access to authorized users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87425. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart