---
cve: "CVE-2025-6391"
severity: "HIGH"
cvss: 7.1
epss: "0.2%"
vendor: "Broadcom"
kev: false
exploited: false
published: "2025-07-17 22:15:26"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-21T08:28:46+02:00"
---

# CVE-2025-6391

> 7.1 HIGH

## Beschreibung

Brocade ASCG before 3.3.0 logs JSON 
Web Tokens (JWT) in log files. An attacker with access to the log files 
 can withdraw the unencrypted tokens with security implications, such as
 unauthorized access, session hijacking, and information disclosure.

## CVSS-Vektor

```
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Lokal | good |
| AC Komplexität | Gering | bad |
| PR Privilegien | Hoch | good |
| UI Interaktion | Keine | bad |

## Referenzen

- <https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/35951>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2025-6391) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
