Security Flaw in Brocade ASCG Affects Multiple URL Paths
CVE-2023-5648
6.5MEDIUM
What is CVE-2023-5648?
The Brocade ASCG prior to version 3.0 exhibits a significant vulnerability due to missing security-related HTTP headers across various URL paths. This oversight permits unauthenticated attackers to exploit the system, leading to potential Cross-Site Scripting (XSS), Clickjacking, and information disclosure attacks. To mitigate these risks, it is critical for users to upgrade to the latest version and implement best practices in security header configuration.
Affected Version(s)
Active Support Connectivity Gateway 0 < 3.0