Brocade

Active Support Connectivity Gateway

14 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.17%
  • Veröffentlicht 08.10.2026 07:16:33
  • Zuletzt bearbeitet 08.10.2026 07:16:33

A vulnerability in the SupportLink API authentication component of Brocade ASCG versions prior to 3.5.0 allows an attacker to bypass authentication across deployments due to the use of a hard coded cryptographic key.

  • EPSS 0.1%
  • Veröffentlicht 08.10.2026 07:16:33
  • Zuletzt bearbeitet 08.10.2026 07:16:33

An unauthenticated remote attacker can modify the TLS client trust store in Brocade ASCG versions before 3.5.0. By supplying an unauthorized Certificate Authority (CA) certificate to an unauthenticated management interface, the attacker can cause the...

  • EPSS 0.15%
  • Veröffentlicht 08.10.2026 07:16:33
  • Zuletzt bearbeitet 08.10.2026 07:16:33

An unauthenticated network-based attacker can query specific internal management endpoints on Brocade ASCG versions before 3.5.0 to enumerate the configuration details and state of managed Brocade Fabric OS (FOS) switches. This results in the unautho...

  • EPSS 0.1%
  • Veröffentlicht 08.10.2026 07:16:33
  • Zuletzt bearbeitet 08.10.2026 07:16:33

In Brocade ASCG before 3.5.0, a  local unauthorized user on the ASCG VM who can issue a request to the SANnav host network namespace can extract stored management credentials for onboarded SANnav instances and compromise connected Brocade SANnav serv...

  • EPSS 0.27%
  • Veröffentlicht 08.10.2026 06:42:43
  • Zuletzt bearbeitet 08.10.2026 07:16:32

When Brocade ASCG before 3.5.0 processes support bundle archives ingested from remote compromised endpoints, the application fails to sanitize path traversal sequences contained within archive entries prior to extraction. An unauthenticated remote at...

  • EPSS 0.19%
  • Veröffentlicht 08.10.2026 06:39:59
  • Zuletzt bearbeitet 08.10.2026 07:16:32

An authentication flaw exists in the Brocade ASCG administrative management service component. An unauthenticated network user can issue direct API requests to perform privileged actions, including accessing sensitive system configuration mapping dat...

  • EPSS 0.09%
  • Veröffentlicht 08.10.2026 06:36:17
  • Zuletzt bearbeitet 08.10.2026 07:16:32

Brocade ASCG before 3.5.0 has a well-known Brocade default password embedded in a script distributed to every customer. Any local authenticated user with read access to the installation path can discover this credential and perform privilege escalati...

  • EPSS 0.21%
  • Veröffentlicht 08.10.2026 06:32:03
  • Zuletzt bearbeitet 08.10.2026 07:16:32

A path traversal vulnerability exists in the HTTP service component of Brocade ASCG versions before 3.5.0. An unauthenticated attacker on the local network could send a manipulated API request to the service endpoint bypassing path restrictions to ar...

  • EPSS 0.23%
  • Veröffentlicht 08.10.2026 06:29:31
  • Zuletzt bearbeitet 08.10.2026 07:16:32

Brocade ASCG before 3.5.0 improperly processes user input by evaluating form data prior to validation. When an authenticated user submits a configuration form, the submitted text could immediately be processed. A malicious actor with basic access can...

  • EPSS 0.21%
  • Veröffentlicht 08.10.2026 06:25:40
  • Zuletzt bearbeitet 08.10.2026 07:16:32

A vulnerability has been identified in the data collection service of Brocade ASCG versions before 3.5.0. An API endpoint within the data collector service fails to perform authentication or authorization checks on incoming requests. An attacker with...