PT-2026-107855 · Brocade · Ascg
CVE-2026-85486
·
Published
2026-10-08
·
Updated
2026-10-08
CVSS v4.0
8.6
High
| Vector | AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Brocade ASCG versions prior to 3.5.0
Description
An issue exists where the system improperly processes user input by evaluating form data before validation. An authenticated user with basic access can submit crafted input through a configuration form, allowing for arbitrary code execution on the server and full control of the application.
Recommendations
Update Brocade ASCG to version 3.5.0 or later.
Fix
Eval Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ascg