Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Security update is provided in Brocade ASCG 3.0
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Missing Security Headers Enable Unauthenticated XSS and Clickjacking on Brocade ASCG |
Thu, 08 Oct 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Brocade
Brocade active Support Connectivity Gateway |
|
| Vendors & Products |
Brocade
Brocade active Support Connectivity Gateway |
Thu, 08 Oct 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Brocade ASCG before Brocade ASCG v3.0, several security-related HTTP Headers were missing in various Brocade ASCG URL paths, aiding unauthenticated attackers to perform attacks such as Cross-Site Scripting, Clickjacking, Information disclosure, and more. | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: brocade
Published:
Updated: 2026-10-08T04:56:08.687Z
Reserved: 2023-10-19T01:32:22.948Z
Link: CVE-2023-5648
No data.
Status : Received
Published: 2026-10-08T05:17:03.747
Modified: 2026-10-08T05:17:03.747
Link: CVE-2023-5648
No data.
OpenCVE Enrichment
Updated: 2026-10-08T08:00:16Z