CVE-2024-1509
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
28/02/2025
Last modified:
28/02/2025
Description
Brocade ASCG before 3.2.0 Web Interface is not <br />
enforcing HSTS, as defined by RFC 6797. HSTS is an optional response <br />
header that can be configured on the server to instruct the browser to <br />
only communicate via HTTPS. The lack of HSTS allows downgrade attacks, <br />
SSL-stripping man-in-the-middle attacks, and weakens cookie-hijacking <br />
protections.
Impact
Base Score 4.0
7.60
Severity 4.0
HIGH