PatchSiren cyber security CVE debrief
CVE-2023-5649 Brocade CVE debrief
A local authenticated user could provide invalid inputs to Brocade ASCG before v3.0, leading to a Denial of Service (DoS) when collecting 'supportsave' from a Brocade Switch. This Improper Input Validation vulnerability has a medium severity and requires system administrators and security teams to assess exposure and prioritize remediation to prevent potential Denial of Service (DoS) incidents. The vulnerability is exploitable by local authenticated users, and its exploitation could lead to service disruption.
- Vendor
- Brocade
- Product
- Brocade Active Support Connectivity Gateway
- CVSS
- MEDIUM 6.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
System administrators and security teams responsible for Brocade ASCG systems should assess exposure and prioritize remediation to prevent potential Denial of Service (DoS) incidents.
Why it matters
CVE-2023-5649 is a medium-severity vulnerability in Brocade ASCG before v3.0, allowing local authenticated users to cause a Denial of Service (DoS). System administrators and security teams should assess exposure, prioritize remediation, and implement input validation and sanitization to prevent potential incidents.
- Denial of Service (DoS) incidents may occur if the vulnerability is exploited.
- System administrators and security teams must verify Brocade ASCG versions and configurations to ensure they are not vulnerable.
- Remediation priority is medium, as the vulnerability can be addressed by updating to version 3.0 or later.
Technical summary
The CVE record describes an Improper Input Validation vulnerability in Brocade ASCG before v3.0, which could allow a local authenticated user to provide invalid inputs, leading to a Denial of Service (DoS) when collecting 'supportsave' from a Brocade Switch. The vulnerability has a medium severity and requires defensive actions to address it. The technical details of the vulnerability involve the improper validation of user inputs, which could lead to service disruption. To mitigate this vulnerability, it is essential to review and update Brocade ASCG to version 3.0 or later and implement input validation and sanitization for user-provided data.
Defensive priority
Medium-priority defensive actions are recommended to address the Improper Input Validation vulnerability in Brocade ASCG.
Recommended defensive actions
- Review and update Brocade ASCG to version 3.0 or later to address the vulnerability.
- Implement input validation and sanitization for user-provided data in Brocade ASCG.
- Monitor Brocade ASCG systems for unusual activity or Denial of Service (DoS) incidents.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE record and source item provide limited information about the vulnerability, primarily focusing on the Improper Input Validation issue in Brocade ASCG before v3.0. The evidence is based on the CVE Program record and the source item, which describe the vulnerability and its potential impact. However, additional verification is needed to confirm affected product deployments and assess exposure. The lack of detailed information about the vulnerability's exploitation and affected scope necessitates further investigation and review.
Sources and references
Verified primary and authoritative sources
-
CVE-2023-5649 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-5649
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-5649 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-5649
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
CVE-2023-5649
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2023/5xxx/CVE-2023-5649.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://support.broadcom.com/external/content/SecurityAdvisories/0/22716
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.