Security Flaw in Brocade ASCG Affects Multiple URL Paths
CVE-2023-5648

6.5MEDIUM

Key Information:

Vendor

Brocade

Vendor
CVE Published:
8 October 2026

What is CVE-2023-5648?

The Brocade ASCG prior to version 3.0 exhibits a significant vulnerability due to missing security-related HTTP headers across various URL paths. This oversight permits unauthenticated attackers to exploit the system, leading to potential Cross-Site Scripting (XSS), Clickjacking, and information disclosure attacks. To mitigate these risks, it is critical for users to upgrade to the latest version and implement best practices in security header configuration.

Affected Version(s)

Active Support Connectivity Gateway 0 < 3.0

References

CVSS V4

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.