# CVE-2024-1509

## Summary

- **CVE ID:** CVE-2024-1509
- **Severity:** HIGH
- **CVSS Score:** 7.6 (CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-523
- **Published:** Feb 28, 2025
- **Last Modified:** Mar 13, 2026

## Description

Brocade ASCG before 3.2.0 Web Interface  is not 
enforcing HSTS, as defined by RFC 6797. HSTS is an optional response 
header that can be configured on the server to instruct the browser to 
only communicate via HTTPS. The lack of HSTS allows downgrade attacks, 
SSL-stripping man-in-the-middle attacks, and weakens cookie-hijacking 
protections.

## Affected Products

- Brocade — ASCG (before 3.2.0)

## References

- [CNA](https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25428)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.36%
- **EPSS Percentile:** 29.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._