{"id":"CVE-2023-5648","title":"In Brocade ASCG before Brocade ASCG v3.0, several security-related HTTP Headers were missing in various Brocade ASCG URL paths, aiding unauthenticated attackers to perform attacks such as Cross-Site Scripting, Clickjacking, Information d…","summary":"In Brocade ASCG before Brocade ASCG v3.0, several security-related HTTP Headers were missing in various Brocade ASCG URL paths, aiding unauthenticated attackers to perform attacks such as Cross-Site Scripting, Clickjacking, Information d…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:H/SI:H/SA:H","cwe":["CWE-79"],"vendor":"Brocade","product":"Active Support Connectivity Gateway","affected":["active_support_connectivity_gateway < 3.0"],"published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T05:17:03.747","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2023-5648","references":[{"url":"https://support.broadcom.com/external/content/SecurityAdvisories/0/22715","label":"sirt@brocade.com"}],"tags":["nvd","cve.org"],"cvssSource":"cna","ingestedAt":"2026-10-08T05:05:36.674Z","slug":"CVE-2023-5648","body":"## Overview\n\nIn Brocade ASCG before Brocade ASCG v3.0, several security-related HTTP Headers were missing in various Brocade ASCG URL paths, aiding unauthenticated attackers to perform attacks such as Cross-Site Scripting, Clickjacking, Information disclosure, and more.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}