Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j6jw-hg33-x575

Опубликовано: 01 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 7.6
CVSS3: 9.1

Описание

Brocade ASCG before 3.2.0 Web Interface is not enforcing HSTS, as defined by RFC 6797. HSTS is an optional response header that can be configured on the server to instruct the browser to only communicate via HTTPS. The lack of HSTS allows downgrade attacks, SSL-stripping man-in-the-middle attacks, and weakens cookie-hijacking protections.

Brocade ASCG before 3.2.0 Web Interface is not enforcing HSTS, as defined by RFC 6797. HSTS is an optional response header that can be configured on the server to instruct the browser to only communicate via HTTPS. The lack of HSTS allows downgrade attacks, SSL-stripping man-in-the-middle attacks, and weakens cookie-hijacking protections.

EPSS

Процентиль: 26%
0.00093
Низкий

7.6 High

CVSS4

9.1 Critical

CVSS3

Дефекты

CWE-523

Связанные уязвимости

CVSS3: 9.1
nvd
11 месяцев назад

Brocade ASCG before 3.2.0 Web Interface is not enforcing HSTS, as defined by RFC 6797. HSTS is an optional response header that can be configured on the server to instruct the browser to only communicate via HTTPS. The lack of HSTS allows downgrade attacks, SSL-stripping man-in-the-middle attacks, and weakens cookie-hijacking protections.

EPSS

Процентиль: 26%
0.00093
Низкий

7.6 High

CVSS4

9.1 Critical

CVSS3

Дефекты

CWE-523