Brocade ASCG before 3.3.0 logs JSON Web Tokens (JWT) in log files. An attacker with access to the log files can withdraw the unencrypted tokens with security implications, such as unauthorized access, session hijacking, and information disclosure.
History

Mon, 02 Feb 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Brocade
Brocade ascg
CPEs cpe:2.3:a:brocade:ascg:*:*:*:*:*:*:*:*
Vendors & Products Brocade
Brocade ascg
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Fri, 18 Jul 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Jul 2025 22:00:00 +0000

Type Values Removed Values Added
Description Brocade ASCG before 3.3.0 logs JSON Web Tokens (JWT) in log files. An attacker with access to the log files can withdraw the unencrypted tokens with security implications, such as unauthorized access, session hijacking, and information disclosure.
Title JSON Web Token (JWT) Exposure in Log Files
Weaknesses CWE-532
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published:

Updated: 2025-07-18T14:11:11.224Z

Reserved: 2025-06-20T02:59:00.845Z

Link: CVE-2025-6391

cve-icon Vulnrichment

Updated: 2025-07-18T14:11:07.987Z

cve-icon NVD

Status : Analyzed

Published: 2025-07-17T22:15:26.263

Modified: 2026-02-02T15:22:36.497

Link: CVE-2025-6391

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.