TLS Client Trust Store Vulnerability in Brocade ASCG by Broadcom
CVE-2026-87425

7.6HIGH

Key Information:

Vendor

Brocade

Vendor
CVE Published:
8 October 2026

What is CVE-2026-87425?

A vulnerability exists in Brocade ASCG where an unauthenticated remote attacker can manipulate the TLS client trust store. By introducing an unapproved Certificate Authority (CA) certificate through an exposed management interface, the attacker can compromise the integrity of communication channels, potentially allowing for Man-in-the-Middle (MITM) attacks on outbound connections to managed switches and peer nodes. This flaw highlights the necessity for robust security measures to safeguard against unauthorized certificate modifications.

Affected Version(s)

Brocade Active Support Connectivity Gateway 0 < 3.5.0

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.