Brocade ASCG before 3.3.0 logs JSON Web Tokens (JWT) in log files. An attacker with access to the log files can withdraw the unencrypted tokens with security implications, such as unauthorized access, session hijacking, and information disclosure.
CVSS Vector
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XBroadcom Brocade Active Support Connectivity Gateway
APPBroadcom≤ 3.2.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2026-0869HIGH8.3same product
Authentication bypass in Brocade ASCG 3.4.0 Could allow an unauthorized user to perform ASCG operations relate...
CVE-2025-7398HIGH8.6same product
Brocade ASCG before 3.3.0 allows for the use of medium strength cryptography algorithms on internal ports port...
CVE-2024-1509HIGH7.6same product
Brocade ASCG before 3.2.0 Web Interface is not enforcing HSTS, as defined by RFC 6797. HSTS is an optional r...
CVE-2021-40438CRITICAL9.0⚠ KEVPL ✓same vendor
SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego
CVE-2018-1273CRITICAL9.8⚠ KEVPL ✓same vendor
RCE w Spring Data Commons — podatność property bindera