CVE-2024-1509
Brocade ASCG before 3.2.0 Web Interface is not enforcing HSTS, as defined by RFC 6797. HSTS is an optional response header that can be configured on the server to instruct the browser to only communicate via HTTPS. The lack of HSTS allows downgrade attacks, SSL-stripping man-in-the-middle attacks, and weakens cookie-hijacking protections.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.6
- CVSS vector
- CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.36%
- CWE
- CWE-523
- Published
- 2025-02-28
- Last modified
- 2026-03-13
Affected products
- Brocade ASCG
Weakness type
Related vulnerabilities
- CVE-2026-56587 — HCL IEM was affected with Strict transport security not enforced
- CVE-2026-54784 — CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality
- CVE-2026-8668 — Hardcoded credentials in embedded content
- CVE-2026-8673 — Password re-initialization mechanism sends passwords in plain text
- CVE-2026-23635 — Kiteworks Secure Data Forms has a potential Unprotected Transport of Credentials
- CVE-2025-61916 — Spinnaker vulnerable to SSRF due to improper restrictions on http from user input
- CVE-2025-66029 — Open OnDemand affected by Apache proxy passing sensitive headers
- CVE-2025-64309 — Brightpick Mission Control / Internal Logic Control Unprotected Transport of Credentials