CVE Vulnerabilities

CVE-2024-1509

Unprotected Transport of Credentials

Published: Feb 28, 2025 | Modified: Jan 29, 2026
CVSS 3.x
9.1
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Brocade ASCG before 3.2.0 Web Interface is not enforcing HSTS, as defined by RFC 6797. HSTS is an optional response header that can be configured on the server to instruct the browser to only communicate via HTTPS. The lack of HSTS allows downgrade attacks, SSL-stripping man-in-the-middle attacks, and weakens cookie-hijacking protections.

Weakness

Login pages do not use adequate measures to protect the user name and password while they are in transit from the client to the server.

Affected Software

NameVendorStart VersionEnd Version
Active_support_connectivity_gatewayBrocade*3.2.0 (excluding)

Potential Mitigations

References