Vulnerability Description
Brocade ASCG before 3.3.0 logs JSON Web Tokens (JWT) in log files. An attacker with access to the log files can withdraw the unencrypted tokens with security implications, such as unauthorized access, session hijacking, and information disclosure.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Broadcom | Brocade Active Support Connectivity Gateway | <= 3.2.0 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-6391?
CVE-2025-6391 is a vulnerability with a CVSS score of 9.1 (CRITICAL). Brocade ASCG before 3.3.0 logs JSON Web Tokens (JWT) in log files. An attacker with access to the log files can withdraw the unencrypted tokens with security implications, such as unauthorized acc...
How severe is CVE-2025-6391?
CVE-2025-6391 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-6391?
Check the references section above for vendor advisories and patch information. Affected products include: Broadcom Brocade Active Support Connectivity Gateway.