Back to search
CVE-2025-6391
Published: Jul 17, 2025
Modified: Jul 18, 2025
PUBLISHED
Description
Brocade ASCG before 3.3.0 logs JSON Web Tokens (JWT) in log files. An attacker with access to the log files can withdraw the unencrypted tokens with security implications, such as unauthorized access, session hijacking, and information disclosure.
| Vendor | Product | Versions |
|---|---|---|
Broadcom | Brocade ASCG | affected before 3.3.0 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now