CVE-2026-87425 — An unauthenticated remote attacker can modify the TLS client trust store in Brocade ASCG versions before 3.5.0.
Description
An unauthenticated remote attacker can modify the TLS client trust store in Brocade ASCG versions before 3.5.0. By supplying an unauthorized Certificate Authority (CA) certificate to an unauthenticated management interface, the attacker can cause the system to trust unauthorized certificates, potentially enabling Man-in-the-Middle (MITM) attacks against outbound communications with managed switches and peer nodes.
CVSS v4.0 base metrics
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XHigh severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Adjacent
Attack Vector
AC
Low
Attack Complexity
AT
Present
Attack Requirements
PR
None
Privileges Required
UI
None
User Interaction
VC
High
Confidentiality (Vulnerable System)
VI
High
Integrity (Vulnerable System)
VA
None
Availability (Vulnerable System)
SC
None
Confidentiality (Subsequent System)
SI
None
Integrity (Subsequent System)
SA
None
Availability (Subsequent System)
References
Related threats
same CWE or vendorCVE-2026-96207 — Improper certificate validation in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-96207 · 4h ago
CVE-2026-84032 — IBM Guardium Data Protection 12.2.2 could allow a remote attacker to conduct a man-in-the-middle attack due to improper certificate validation.
CVE-2026-84032 · 5h ago
CVE-2026-107318 — @fastify/reply-from is a Fastify plugin that forwards requests to an upstream HTTP or HTTPS server.
CVE-2026-107318 · 6h ago
CVE-2026-95210 — Improper certificate validation in gnutls v3.8.13 causes the application to accept certificates containing invalid extensions.
CVE-2026-95210 · 9h ago
CVE-2026-95208 — An issue in the ConfirmNameConstraints() function (wolfcrypt/src/asn.c) of wolfSSL v5.9.1 and v5.9.2 allows attackers to cause a Denial of Service …
CVE-2026-95208 · 11h ago
CVE-2026-107587 — Improper certificate validation in the webmail of Progressive Robot hMailServer 6.3.2 through 6.3.5 allows a remote unauthenticated attacker to hav…
CVE-2026-107587 · 15h ago