Authentication bypass in Brocade ASCG 3.4.0 Could allow an unauthorized user to perform ASCG operations related to Brocade Support Link(BSL) and streaming configuration. and could even disable the ASCG application or disable use of BSL data collection on Brocade switches within the fabric.
History

Mon, 09 Mar 2026 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Broadcom
Broadcom brocade Active Support Connectivity Gateway
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:broadcom:brocade_active_support_connectivity_gateway:3.4.0:*:*:*:*:*:*:*
Vendors & Products Broadcom
Broadcom brocade Active Support Connectivity Gateway
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 04 Mar 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 04 Mar 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Brocade
Brocade ascg
Vendors & Products Brocade
Brocade ascg

Tue, 03 Mar 2026 20:15:00 +0000

Type Values Removed Values Added
Description Authentication bypass in Brocade ASCG 3.4.0 Could allow an unauthorized user to perform ASCG operations related to Brocade Support Link(BSL) and streaming configuration. and could even disable the ASCG application or disable use of BSL data collection on Brocade switches within the fabric.
Title Application User custom defined accounts are not properly password protected in Brocade ASCG 3.4.0
Weaknesses CWE-305
References
Metrics cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published: 2026-03-03T19:59:53.312Z

Updated: 2026-03-04T21:19:58.402Z

Reserved: 2026-01-12T23:18:49.312Z

Link: CVE-2026-0869

cve-icon Vulnrichment

Updated: 2026-03-04T21:19:52.583Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-03T20:16:45.797

Modified: 2026-03-09T18:15:12.340

Link: CVE-2026-0869

cve-icon Redhat

No data.