« Volver al listado

Broadcom

Broadcom Raid Controller WEB Interface: vulnerabilidades y CVE

Broadcom Raid Controller WEB Interface tiene 22 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 11 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE22
Últimos 12 meses0
Críticas11
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2023-4344Crítica (9.8)0.70%—15 ago 2023
Broadcom RAID Controller web interface is vulnerable to insufficient randomness due to improper use of ssl.rnd to setup CIM connection
CVE-2023-4343Alta (7.5)0.57%—15 ago 2023
Broadcom RAID Controller web interface is vulnerable due to exposure of sensitive password information in the URL as a URL search parameter
CVE-2023-4342Crítica (9.8)0.70%—15 ago 2023
Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP strict-transport-security policy
CVE-2023-4341Crítica (9.8)0.70%—15 ago 2023
Broadcom RAID Controller is vulnerable to Privilege escalation to root due to creation of insecure folders by Web GUI
CVE-2023-4340Crítica (9.8)0.70%—15 ago 2023
Broadcom RAID Controller is vulnerable to Privilege escalation by taking advantage of the Session prints in the log file
CVE-2023-4339Alta (7.5)0.83%—15 ago 2023
Broadcom RAID Controller web interface is vulnerable to exposure of private keys used for CIM stored with insecure file permissions
CVE-2023-4338Crítica (9.8)0.70%—15 ago 2023
Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not provide X-Content-Type-Options Headers
CVE-2023-4337Crítica (9.8)0.70%—15 ago 2023
Broadcom RAID Controller web interface is vulnerable to improper session handling of managed servers on Gateway installation
CVE-2023-4336Crítica (9.8)0.70%—15 ago 2023
Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard cookies with Secure attribute
CVE-2023-4335Alta (7.5)0.59%—15 ago 2023
Broadcom RAID Controller Web server (nginx) is serving private server-side files without any authentication on Linux
CVE-2023-4334Alta (7.5)0.60%—15 ago 2023
Broadcom RAID Controller Web server (nginx) is serving private files without any authentication
CVE-2023-4333Media (5.5)0.12%—15 ago 2023
Broadcom RAID Controller web interface doesn’t enforce SSL cipher ordering by server
CVE-2023-4332Alta (7.5)0.59%—15 ago 2023
Broadcom RAID Controller web interface is vulnerable due to Improper permissions on the log file
CVE-2023-4331Alta (7.5)0.35%—15 ago 2023
Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that support obsolete and vulnerable TLS protocols
CVE-2023-4329Crítica (9.8)0.70%—15 ago 2023
Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard SESSIONID cookie with SameSite attribute
CVE-2023-4328Media (5.5)0.11%—15 ago 2023
Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Windows
CVE-2023-4327Media (5.5)0.11%—15 ago 2023
Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Linux
CVE-2023-4326Alta (7.5)0.40%—15 ago 2023
Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that supports obsolete SHA1-based ciphersuites
CVE-2023-4325Crítica (9.8)0.70%—15 ago 2023
Broadcom RAID Controller web interface is vulnerable due to usage of Libcurl with LSA has known vulnerabilities
CVE-2023-4324Crítica (9.8)0.70%—15 ago 2023
Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP Content-Security-Policy headers
CVE-2023-4323Crítica (9.8)0.71%—15 ago 2023
Broadcom RAID Controller web interface is vulnerable to improper session management of active sessions on Gateway setup
CVE-2023-4345Media (6.5)0.58%—15 ago 2023
Broadcom RAID Controller web interface is vulnerable client-side control bypass leads to unauthorized data access for low privileged user

Otros productos de Broadcom