Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Security update provided in Brocade ASCG 3.5.0
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 08 Oct 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Improper Input Validation Enables Remote Code Execution in Brocade ASCG |
Thu, 08 Oct 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Brocade ASCG before 3.5.0 improperly processes user input by evaluating form data prior to validation. When an authenticated user submits a configuration form, the submitted text could immediately be processed. A malicious actor with basic access can supply crafted input to execute arbitrary code on the server and take control of the application. | |
| Weaknesses | CWE-95 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: brocade
Published:
Updated: 2026-10-08T17:47:05.065Z
Reserved: 2026-09-03T21:31:03.838Z
Link: CVE-2026-85486
Updated: 2026-10-08T17:46:57.853Z
Status : Received
Published: 2026-10-08T07:16:32.317
Modified: 2026-10-08T18:18:27.943
Link: CVE-2026-85486
No data.
OpenCVE Enrichment
Updated: 2026-10-08T08:00:16Z