Cryptographic Key Exposure in Brocade ASCG Software
CVE-2026-85422

8.4HIGH

Key Information:

Vendor

Brocade

Vendor
CVE Published:
8 October 2026

What is CVE-2026-85422?

A vulnerability in Brocade ASCG versions prior to 3.5.0 allows attackers to access a hardcoded static cryptographic key embedded in the software binaries. This exposure can lead to the decryption of sensitive data, including stored management credentials. Additionally, an attacker could potentially fabricate unauthorized administrative synchronization messages. Organizations using affected versions are urged to upgrade to mitigate these risks.

Affected Version(s)

Brocade Active Support Connectivity Gateway 0 < 3.5.0

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.