CVE-2024-1509 – Brocade ASCG Missing HSTS Configuration Vulnerability

The following table lists the changes that have been made to the
CVE-2024-1509 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Feb. 28, 2025

    Action Type Old Value New Value
    Added Description Brocade ASCG before 3.2.0 Web Interface is not
    enforcing HSTS, as defined by RFC 6797. HSTS is an optional response
    header that can be configured on the server to instruct the browser to
    only communicate via HTTPS. The lack of HSTS allows downgrade attacks,
    SSL-stripping man-in-the-middle attacks, and weakens cookie-hijacking
    protections.
    Added CVSS V4.0 AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    Added CWE CWE-523
    Added Reference https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25428
Share the Post:

Related Posts