Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Security update provided in Brocade ASCG 3.5.0
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Default Password Leakage Enabling Local Privilege Escalation in Brocade ASCG |
Thu, 08 Oct 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Brocade ASCG before 3.5.0 has a well-known Brocade default password embedded in a script distributed to every customer. Any local authenticated user with read access to the installation path can discover this credential and perform privilege escalation on affected Open Virtual Appliance (OVA) deployments, where default configuration settings remain in place. | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: brocade
Published:
Updated: 2026-10-08T17:46:32.025Z
Reserved: 2026-09-03T21:31:03.838Z
Link: CVE-2026-85488
No data.
Status : Received
Published: 2026-10-08T07:16:32.590
Modified: 2026-10-08T07:16:32.590
Link: CVE-2026-85488
No data.
OpenCVE Enrichment
Updated: 2026-10-08T08:00:16Z
