Brocade ASCG before 3.5.0 improperly processes user input by evaluating form data prior to validation. When an authenticated user submits a configuration form, the submitted text could immediately be processed. A malicious actor with basic access can supply crafted input to execute arbitrary code on the server and take control of the application.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Security update provided in Brocade ASCG 3.5.0
Workaround
No workaround given by the vendor.
References
History
Thu, 08 Oct 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Improper Input Validation Enables Remote Code Execution in Brocade ASCG |
Thu, 08 Oct 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Brocade ASCG before 3.5.0 improperly processes user input by evaluating form data prior to validation. When an authenticated user submits a configuration form, the submitted text could immediately be processed. A malicious actor with basic access can supply crafted input to execute arbitrary code on the server and take control of the application. | |
| Weaknesses | CWE-95 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: brocade
Published:
Updated: 2026-10-08T06:29:31.210Z
Reserved: 2026-09-03T21:31:03.838Z
Link: CVE-2026-85486
No data.
Status : Received
Published: 2026-10-08T07:16:32.317
Modified: 2026-10-08T07:16:32.317
Link: CVE-2026-85486
No data.
OpenCVE Enrichment
Updated: 2026-10-08T08:00:16Z
Weaknesses