Brocade ASCG before 3.2.0 Web Interface is not
enforcing HSTS, as defined by RFC 6797. HSTS is an optional response
header that can be configured on the server to instruct the browser to
only communicate via HTTPS. The lack of HSTS allows downgrade attacks,
SSL-stripping man-in-the-middle attacks, and weakens cookie-hijacking
protections.
CVE ID: CVE-2024-1509
CVSS Base Severity: HIGH
CVSS Base Score: 7.6
CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Vendor: Brocade
Product: ASCG
EPSS Score: 0.02% (probability of being exploited)
EPSS Percentile: 2.12% (scored less or equal to compared to others)
EPSS Date: 2025-03-29 (when was this score calculated)