Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Security update provided in Brocade ASCG 3.5.0
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 08 Oct 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated API Access Allows Privileged Configuration Changes in Brocade ASCG |
Thu, 08 Oct 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authentication flaw exists in the Brocade ASCG administrative management service component. An unauthenticated network user can issue direct API requests to perform privileged actions, including accessing sensitive system configuration mapping data, modifying managed device inventories, and altering operational settings. This vulnerability affects all versions of Brocade ASCG before 3.5.0. | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: brocade
Published:
Updated: 2026-10-08T17:45:58.708Z
Reserved: 2026-09-03T21:31:03.838Z
Link: CVE-2026-85489
Updated: 2026-10-08T17:45:52.149Z
Status : Received
Published: 2026-10-08T07:16:32.727
Modified: 2026-10-08T18:18:28.323
Link: CVE-2026-85489
No data.
OpenCVE Enrichment
Updated: 2026-10-08T07:30:13Z