CVE-2023-5648
Received Received - Intake

Missing Security Headers in Brocade ASCG

Vulnerability report for CVE-2023-5648, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: Brocade Communications Systems, LLC

Description

In Brocade ASCG before Brocade ASCG v3.0, several security-related HTTP Headers were missing in various Brocade ASCG URL paths, aiding unauthenticated attackers to perform attacks such as Cross-Site Scripting, Clickjacking, Information disclosure, and more.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Brocade Active Support Connectivity Gateway 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves missing security-related HTTP headers in Brocade ASCG before v3.0. These headers are crucial for protecting against attacks like Cross-Site Scripting, Clickjacking, and Information disclosure. Without them, unauthenticated attackers could exploit these weaknesses.

Detection Guidance

Detect missing security headers by inspecting HTTP responses from Brocade ASCG URLs using tools like curl or browser developer tools. Check for absence of headers such as X-Frame-Options, X-Content-Type-Options, and Content-Security-Policy.

Impact Analysis

The missing headers could allow attackers to perform Cross-Site Scripting, Clickjacking, or Information disclosure attacks. This may lead to unauthorized access to sensitive data, manipulation of user sessions, or exposure of confidential information.

Compliance Impact

The vulnerability's lack of security headers could lead to information disclosure, which may violate GDPR's data protection requirements and HIPAA's safeguards for protected health information. Cross-site scripting risks could also compromise data integrity and confidentiality under these regulations.

Mitigation Strategies

Update Brocade ASCG to v3.0 or later to ensure security headers are present. If immediate update is not possible, manually configure missing security headers in the web server or application configuration.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2023-5648. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart