CVE-2024-1509

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
28/02/2025
Last modified:
28/02/2025

Description

Brocade ASCG before 3.2.0 Web Interface is not <br /> enforcing HSTS, as defined by RFC 6797. HSTS is an optional response <br /> header that can be configured on the server to instruct the browser to <br /> only communicate via HTTPS. The lack of HSTS allows downgrade attacks, <br /> SSL-stripping man-in-the-middle attacks, and weakens cookie-hijacking <br /> protections.