CVE-2025-6391

EUVD-2025-21828
Brocade ASCG before 3.3.0 logs JSON 
Web Tokens (JWT) in log files. An attacker with access to the log files 
 can withdraw the unencrypted tokens with security implications, such as
 unauthorized access, session hijacking, and information disclosure.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.1 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
broadcombrocade_active_support_connectivity_gateway
𝑥
≤ 3.2.0
𝑥
= Vulnerable software versions