CVE-2024-1509

EUVD-2024-17257
Brocade ASCG before 3.2.0 Web Interface  is not 
enforcing HSTS, as defined by RFC 6797. HSTS is an optional response 
header that can be configured on the server to instruct the browser to 
only communicate via HTTPS. The lack of HSTS allows downgrade attacks, 
SSL-stripping man-in-the-middle attacks, and weakens cookie-hijacking 
protections.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.1 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 26%
Affected Products (NVD)
VendorProductVersion
brocadeactive_support_connectivity_gateway
𝑥
< 3.2.0
𝑥
= Vulnerable software versions