Broadcom Broadcom

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Broadcom product.

Products by Broadcom Sorted by Most Security Vulnerabilities since 2018

Broadcom Brocade Sannav43 vulnerabilities

Broadcom Tcpreplay40 vulnerabilities

Broadcom Sannav15 vulnerabilities

Broadcom Content Analysis4 vulnerabilities

By the Year

In 2025 there have been 0 vulnerabilities in Broadcom. Last year, in 2024 Broadcom had 41 security vulnerabilities published. Right now, Broadcom is on track to have less security vulnerabilities in 2025 than it did last year.




Year Vulnerabilities Average Score
2025 0 0.00
2024 41 6.97
2023 59 7.33
2022 61 7.48
2021 44 6.81
2020 46 7.33
2019 31 7.45
2018 44 7.52

It may take a day or so for new Broadcom vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Broadcom Security Vulnerabilities

Brocade Fabric OS SFTP/FTP Server Password Exposure in Core Dump

CVE-2024-10403 7.5 - High - November 21, 2024

Brocade Fabric OS versions before 8.2.3e2, versions 9.0.0 through 9.2.0c, and 9.2.1 through 9.2.1a can capture the SFTP/FTP server password used for a firmware download operation initiated by SANnav or through WebEM in a weblinker core dump that is later captured via supportsave.

Files or Directories Accessible to External Parties

Brocade SANnav Information Exposure Through Log Files

CVE-2022-43933 4.4 - Medium - November 21, 2024

An information exposure through log file vulnerability exists in Brocade SANnav before Brocade SANnav 2.2.2, where configuration secrets are logged in supportsave. Supportsave file is generated by an admin user troubleshooting the switch. The Logged information may include usernames and passwords, and secret keys.

Insertion of Sensitive Information into Log File

Brocade SANnav Weak Key Exchange Algorithm Vulnerability

CVE-2022-43934 7.5 - High - November 21, 2024

Brocade SANnav before Brocade SANnav 2.2.2 supports key exchange algorithms, which are considered weak on ports 24, 6514, 18023, 19094, and 19095.

Use of a Broken or Risky Cryptographic Algorithm

Brocade SANnav Information Exposure through Log Files

CVE-2022-43935 4.4 - Medium - November 21, 2024

An information exposure through log file vulnerability exists in Brocade SANnav before Brocade SANnav 2.2.2, where Brocade Fabric OS Switch passwords and authorization IDs are printed in the embedded MLS DB file.

Insertion of Sensitive Information into Log File

Brocade SANnav Password Logging Vulnerability in Brocade Fabric OS

CVE-2022-43936 4.9 - Medium - November 21, 2024

Brocade SANnav versions before 2.2.2 log Brocade Fabric OS switch passwords when debugging is enabled.

Insertion of Sensitive Information into Log File

Brocade SANnav: Information Exposure via Debug Logs

CVE-2022-43937 5.5 - Medium - November 21, 2024

Possible information exposure through log file vulnerability where sensitive fields are recorded in the debug-enabled logs when debugging is turned on in Brocade SANnav before 2.3.0 and 2.2.2a

Insertion of Sensitive Information into Log File

A vulnerability in Brocade Fabric OS versions before 9.2.2 could allow man-in-the-middle attackers to conduct remote Service Session Hijacking

CVE-2024-7516 7.1 - High - November 12, 2024

A vulnerability in Brocade Fabric OS versions before 9.2.2 could allow man-in-the-middle attackers to conduct remote Service Session Hijacking that may arise from the attacker's ability to forge an SSH key while the Brocade Fabric OS Switch is performing various remote operations initiated by a switch admin.

Missing Authentication for Critical Function

A reflected cross-site scripting (XSS) vulnerability exists in the PAM UI web interface

CVE-2024-38493 6.1 - Medium - July 15, 2024

A reflected cross-site scripting (XSS) vulnerability exists in the PAM UI web interface. A remote attacker able to convince a PAM user to click on a specially crafted link to the PAM UI web interface could potentially execute arbitrary client-side code in the context of PAM UI.

XSS

RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who

CVE-2024-3596 9 - Critical - July 09, 2024

RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.

Improper Validation of Integrity Check Value

A vulnerability in a password management API in Brocade Fabric OS versions before v9.2.1

CVE-2024-29954 5.5 - Medium - June 26, 2024

A vulnerability in a password management API in Brocade Fabric OS versions before v9.2.1, v9.2.0b, v9.1.1d, and v8.2.3e prints sensitive information in log files. This could allow an authenticated user to view the server passwords for protocols such as scp and sftp. Detail. When the firmwaredownload command is incorrectly entered or points to an erroneous file, the firmware download log captures the failed command, including any password entered in the command line.

Insertion of Sensitive Information into Log File

A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Brocade Fabric OS versions before v9.0.0 could

CVE-2024-5460 8.1 - High - June 26, 2024

A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Brocade Fabric OS versions before v9.0.0 could allow an authenticated, remote attacker to read data from an affected device via SNMP. The vulnerability is due to hard-coded, default community string in the configuration file for the SNMP daemon. An attacker could exploit this vulnerability by using the static community string in SNMP version 1 queries to an affected device.

Use of Hard-coded Credentials

A vulnerability in the web interface in Brocade Fabric OS before v9.2.1

CVE-2024-29953 4.3 - Medium - June 26, 2024

A vulnerability in the web interface in Brocade Fabric OS before v9.2.1, v9.2.0b, and v9.1.1d prints encoded session passwords on session storage for Virtual Fabric platforms. This could allow an authenticated user to view other users' session encoded passwords.

Insecure Storage of Sensitive Information

The PostgreSQL implementation in Brocade SANnav versions before 2.3.0a is vulnerable to an incorrect local authentication flaw

CVE-2024-2860 7.8 - High - May 08, 2024

The PostgreSQL implementation in Brocade SANnav versions before 2.3.0a is vulnerable to an incorrect local authentication flaw. An attacker accessing the VM where the Brocade SANnav is installed can gain access to sensitive data inside the PostgreSQL database.

Missing Authentication for Critical Function

A vulnerability in Brocade SANnav exposes Kafka in the wan interface

CVE-2024-4173 9.8 - Critical - April 25, 2024

A vulnerability in Brocade SANnav exposes Kafka in the wan interface. The vulnerability could allow an unauthenticated attacker to perform various attacks, including DOS against the Brocade SANnav.

Brocade SANnav before v2.3.0a lacks protection mechanisms on port 2377/TCP and 7946/TCP, which could

CVE-2024-4159 5.3 - Medium - April 25, 2024

Brocade SANnav before v2.3.0a lacks protection mechanisms on port 2377/TCP and 7946/TCP, which could allow an unauthenticated attacker to sniff the SANnav Docker information.

In Brocade SANnav, before Brocade SANnav v2.3.0, syslog traffic received clear text

CVE-2024-4161 7.5 - High - April 25, 2024

In Brocade SANnav, before Brocade SANnav v2.3.0, syslog traffic received clear text. This could allow an unauthenticated, remote attacker to capture sensitive information.

Cleartext Transmission of Sensitive Information

An information disclosure vulnerability exists in Brocade SANnav before v2.3.1 and v2.3.0a when Brocade SANnav instances are configured in disaster recovery mode

CVE-2024-29968 6.5 - Medium - April 19, 2024

An information disclosure vulnerability exists in Brocade SANnav before v2.3.1 and v2.3.0a when Brocade SANnav instances are configured in disaster recovery mode. SQL Table names, column names, and SQL queries are collected in DR standby Supportsave. This could allow authenticated users to access the database structure and its contents.

Insecure Storage of Sensitive Information

When a Brocade SANnav installation is upgraded

CVE-2024-29969 7.5 - High - April 19, 2024

When a Brocade SANnav installation is upgraded from Brocade SANnav v2.2.2 to Brocade SANnav 2.3.0, TLS/SSL weak message authentication code ciphers are added by default for port 18082.

Inadequate Encryption Strength

Brocade SANnav OVA before v2.3.1 and v2.3.0a have an insecure file permission setting that makes files world-readable

CVE-2024-29962 5.5 - Medium - April 19, 2024

Brocade SANnav OVA before v2.3.1 and v2.3.0a have an insecure file permission setting that makes files world-readable. This could allow a local user without the required privileges to access sensitive information or a Java binary.

Incorrect Default Permissions

Brocade SANnav versions before v2.3.0a do not correctly set permissions on files, including docker files

CVE-2024-29964 6.5 - Medium - April 19, 2024

Brocade SANnav versions before v2.3.0a do not correctly set permissions on files, including docker files. An unprivileged attacker who gains access to the server can read sensitive information from these files.

Incorrect Permission Assignment for Critical Resource

In Brocade SANnav before v2.3.1, and v2.3.0a, it is possible to back up the appliance

CVE-2024-29965 5.9 - Medium - April 19, 2024

In Brocade SANnav before v2.3.1, and v2.3.0a, it is possible to back up the appliance from the web interface or the command line interface ("SSH"). The resulting backups are world-readable. A local attacker can recover backup files, restore them to a new malicious appliance, and retrieve the passwords of all the switches.

Insecure Storage of Sensitive Information

Brocade SANnav OVA before v2.3.1 and v2.3.0a contain hard-coded credentials in the documentation

CVE-2024-29966 9.8 - Critical - April 19, 2024

Brocade SANnav OVA before v2.3.1 and v2.3.0a contain hard-coded credentials in the documentation that appear as the appliance's root password. The vulnerability could allow an unauthenticated attacker full access to the Brocade SANnav appliance.

Use of Hard-coded Credentials

In Brocade SANnav before Brocade SANnav v2.31 and v2.3.0a, it was observed

CVE-2024-29967 6 - Medium - April 19, 2024

In Brocade SANnav before Brocade SANnav v2.31 and v2.3.0a, it was observed that Docker instances inside the appliance have insecure mount points, allowing reading and writing access to sensitive files. The vulnerability could allow a sudo privileged user on the host OS to read and write access to these files.

Incorrect Default Permissions

When Brocade SANnav before v2.3.1 and v2.3.0a servers are configured in Disaster Recovery mode

CVE-2024-29957 7.5 - High - April 19, 2024

When Brocade SANnav before v2.3.1 and v2.3.0a servers are configured in Disaster Recovery mode, the encryption key is stored in the DR log files. This could provide attackers with an additional, less-protected path to acquiring the encryption key.

Insertion of Sensitive Information into Log File

A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints the encryption key in the console when a privileged user executes the script to replace the Brocade SANnav Management Portal standby node

CVE-2024-29958 6.5 - Medium - April 19, 2024

A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints the encryption key in the console when a privileged user executes the script to replace the Brocade SANnav Management Portal standby node. This could provide attackers an additional, less protected path to acquiring the encryption key.

Insertion of Sensitive Information into Log File

A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints Brocade Fabric OS switch encrypted passwords in the Brocade SANnav Standby node's support save.

CVE-2024-29959 8.6 - High - April 19, 2024

A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints Brocade Fabric OS switch encrypted passwords in the Brocade SANnav Standby node's support save.

Insertion of Sensitive Information into Log File

In Brocade SANnav server before v2.3.1 and v2.3.0a

CVE-2024-29960 7.5 - High - April 19, 2024

In Brocade SANnav server before v2.3.1 and v2.3.0a, the SSH keys inside the OVA image are identical in the VM every time SANnav is installed. Any Brocade SAnnav VM based on the official OVA images is vulnerable to MITM over SSH. An attacker can decrypt and compromise the SSH traffic to the SANnav.

Use of Hard-coded Credentials

A vulnerability affects Brocade SANnav before v2.3.1 and v2.3.0a

CVE-2024-29961 8.2 - High - April 19, 2024

A vulnerability affects Brocade SANnav before v2.3.1 and v2.3.0a. It allows a Brocade SANnav service to send ping commands in the background at regular intervals to gridgain.com to check if updates are available for the Component. This could make an unauthenticated, remote attacker aware of the behavior and launch a supply-chain attack against a Brocade SANnav appliance.

Brocade SANnav OVA before v2.3.1, and v2.3.0a, contain hardcoded TLS keys used by Docker

CVE-2024-29963 3.8 - Low - April 19, 2024

Brocade SANnav OVA before v2.3.1, and v2.3.0a, contain hardcoded TLS keys used by Docker. Note: Brocade SANnav doesn't have access to remote Docker registries.

Use of Hard-coded Credentials

A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints the Brocade SANnav password in clear text in supportsave logs when a user schedules a switch Supportsave

CVE-2024-29956 6.5 - Medium - April 18, 2024

A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints the Brocade SANnav password in clear text in supportsave logs when a user schedules a switch Supportsave from Brocade SANnav.

Cleartext Storage of Sensitive Information

A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could

CVE-2024-29952 5.5 - Medium - April 17, 2024

A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow an authenticated user to print the Auth, Priv, and SSL key store passwords in unencrypted logs by manipulating command variables.

Cleartext Storage of Sensitive Information

A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could

CVE-2024-29955 5.5 - Medium - April 17, 2024

A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow a privileged user to print the SANnav encrypted key in PostgreSQL startup logs. This could provide attackers with an additional, less-protected path to acquiring the encryption key.

Insertion of Sensitive Information into Log File

Brocade SANnav before v2.3.1 and v2.3.0a uses the SHA-1 hash in internal SSH ports

CVE-2024-29951 5.7 - Medium - April 17, 2024

Brocade SANnav before v2.3.1 and v2.3.0a uses the SHA-1 hash in internal SSH ports that are not open to remote connection.

Inadequate Encryption Strength

The class FileTransfer implemented in Brocade SANnav before v2.3.1, v2.3.0a, uses the ssh-rsa signature scheme, which has a SHA-1 hash

CVE-2024-29950 5.9 - Medium - April 17, 2024

The class FileTransfer implemented in Brocade SANnav before v2.3.1, v2.3.0a, uses the ssh-rsa signature scheme, which has a SHA-1 hash. The vulnerability could allow a remote, unauthenticated attacker to perform a man-in-the-middle attack.

Inadequate Encryption Strength

Brocade Web Interface in Brocade Fabric OS v9.x and before v9.2.0 does not properly represent the portName to the user if the portName contains reserved characters

CVE-2023-5973 4.3 - Medium - April 05, 2024

Brocade Web Interface in Brocade Fabric OS v9.x and before v9.2.0 does not properly represent the portName to the user if the portName contains reserved characters. This could allow an authenticated user to alter the UI of the Brocade Switch and change ports display.

Origin Validation Error

Remote code execution (RCE) vulnerability in Brocade Fabric OS after v9.0 and before v9.2.0 could

CVE-2023-3454 9.8 - Critical - April 04, 2024

Remote code execution (RCE) vulnerability in Brocade Fabric OS after v9.0 and before v9.2.0 could allow an attacker to execute arbitrary code and use this to gain root access to the Brocade switch.

Shell injection

A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 10.5 and before

CVE-2024-23615 9.8 - Critical - January 26, 2024

A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 10.5 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as root.

Classic Buffer Overflow

A buffer overflow vulnerability exists in Symantec Deployment Solution version 7.9 when parsing UpdateComputer tokens

CVE-2024-23613 9.8 - Critical - January 26, 2024

A buffer overflow vulnerability exists in Symantec Deployment Solution version 7.9 when parsing UpdateComputer tokens. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as SYSTEM.

Classic Buffer Overflow

A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 9.5 and before

CVE-2024-23614 9.8 - Critical - January 26, 2024

A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 9.5 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as root.

Classic Buffer Overflow

A buffer overflow vulnerability exists in Symantec Server Management Suite version 7.9 and before

CVE-2024-23616 9.8 - Critical - January 26, 2024

A buffer overflow vulnerability exists in Symantec Server Management Suite version 7.9 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as SYSTEM.

Classic Buffer Overflow

A buffer overflow vulnerability exists in Symantec Data Loss Prevention version 14.0.2 and before

CVE-2024-23617 8.8 - High - January 26, 2024

A buffer overflow vulnerability exists in Symantec Data Loss Prevention version 14.0.2 and before. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a crafted document to achieve code execution.

Classic Buffer Overflow

Within tcpreplay's tcprewrite

CVE-2023-4256 5.5 - Medium - December 21, 2023

Within tcpreplay's tcprewrite, a double free vulnerability has been identified in the tcpedit_dlt_cleanup() function within plugins/dlt_plugins.c. This vulnerability can be exploited by supplying a specifically crafted file to the tcprewrite binary. This flaw enables a local attacker to initiate a Denial of Service (DoS) attack.

Double-free

Jaspersoft Clarity PPM version 14.3.0.298 was discovered to contain an arbitrary file upload vulnerability

CVE-2023-37790 5.4 - Medium - November 09, 2023

Jaspersoft Clarity PPM version 14.3.0.298 was discovered to contain an arbitrary file upload vulnerability via the Profile Picture Upload function.

XSS

Possible information exposure through log file vulnerability where sensitive fields are recorded in the configuration log without masking on Brocade SANnav before v2.3.0 and 2.2.2a

CVE-2023-31423 5.5 - Medium - August 31, 2023

Possible information exposure through log file vulnerability where sensitive fields are recorded in the configuration log without masking on Brocade SANnav before v2.3.0 and 2.2.2a. Notes: To access the logs, the local attacker must have access to an already collected Brocade SANnav "supportsave" outputs.

Cleartext Storage of Sensitive Information

Brocade SANnav Web interface before Brocade SANnav v2.3.0 and v2.2.2a

CVE-2023-31424 9.8 - Critical - August 31, 2023

Brocade SANnav Web interface before Brocade SANnav v2.3.0 and v2.2.2a allows remote unauthenticated users to bypass web authentication and authorization.

Brocade SANnav before v2.3.0 and v2.2.2a stores SNMPv3 Authentication passwords in plaintext

CVE-2023-31925 6.5 - Medium - August 31, 2023

Brocade SANnav before v2.3.0 and v2.2.2a stores SNMPv3 Authentication passwords in plaintext. A privileged user could retrieve these credentials with knowledge and access to these log files. SNMP credentials could be seen in SANnav SupportSave if the capture is performed after an SNMP configuration failure causes an SNMP communication log dump.

Cleartext Storage of Sensitive Information

In Brocade Fabric OS before v9.2.0a, a local authenticated privileged user

CVE-2023-4163 4.4 - Medium - August 31, 2023

In Brocade Fabric OS before v9.2.0a, a local authenticated privileged user can trigger a buffer overflow condition, leading to a kernel panic with large input to buffers in the portcfgfportbuffers command.

Classic Buffer Overflow

The firmwaredownload command on Brocade Fabric OS v9.2.0 could log the FTP/SFTP/SCP server password in clear text in the SupportSave file when performing a downgrade

CVE-2023-3489 7.5 - High - August 31, 2023

The firmwaredownload command on Brocade Fabric OS v9.2.0 could log the FTP/SFTP/SCP server password in clear text in the SupportSave file when performing a downgrade from Fabric OS v9.2.0 to any earlier version of Fabric OS.

Cleartext Storage of Sensitive Information

Broadcom RAID Controller web interface doesnt enforce SSL cipher ordering by server

CVE-2023-4333 5.5 - Medium - August 15, 2023

Broadcom RAID Controller web interface doesnt enforce SSL cipher ordering by server

Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Linux

CVE-2023-4327 5.5 - Medium - August 15, 2023

Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Linux

Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Windows

CVE-2023-4328 5.5 - Medium - August 15, 2023

Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Windows

Broadcom RAID Controller web interface is vulnerable to improper session management of active sessions on Gateway setup

CVE-2023-4323 9.8 - Critical - August 15, 2023

Broadcom RAID Controller web interface is vulnerable to improper session management of active sessions on Gateway setup

Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP Content-Security-Policy headers

CVE-2023-4324 9.8 - Critical - August 15, 2023

Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP Content-Security-Policy headers

Broadcom RAID Controller web interface is vulnerable due to usage of Libcurl with LSA has known vulnerabilities

CVE-2023-4325 9.8 - Critical - August 15, 2023

Broadcom RAID Controller web interface is vulnerable due to usage of Libcurl with LSA has known vulnerabilities

Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration

CVE-2023-4326 7.5 - High - August 15, 2023

Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that supports obsolete SHA1-based ciphersuites

Use of a Broken or Risky Cryptographic Algorithm

Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration

CVE-2023-4329 9.8 - Critical - August 15, 2023

Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard SESSIONID cookie with SameSite attribute

** REJECT ** Broadcom were unable to duplicate the attack as described by Intel DCG Team.

CVE-2023-4330 - August 15, 2023

** REJECT ** Broadcom were unable to duplicate the attack as described by Intel DCG Team.

Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration

CVE-2023-4331 7.5 - High - August 15, 2023

Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that support obsolete and vulnerable TLS protocols

Use of a Broken or Risky Cryptographic Algorithm

Broadcom RAID Controller web interface is vulnerable due to Improper permissions on the log file

CVE-2023-4332 7.5 - High - August 15, 2023

Broadcom RAID Controller web interface is vulnerable due to Improper permissions on the log file

Incorrect Permission Assignment for Critical Resource

Broadcom RAID Controller Web server (nginx) is serving private files without any authentication

CVE-2023-4334 7.5 - High - August 15, 2023

Broadcom RAID Controller Web server (nginx) is serving private files without any authentication

Missing Authentication for Critical Function

Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration

CVE-2023-4336 9.8 - Critical - August 15, 2023

Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard cookies with Secure attribute

Broadcom RAID Controller web interface is vulnerable to improper session handling of managed servers on Gateway installation

CVE-2023-4337 9.8 - Critical - August 15, 2023

Broadcom RAID Controller web interface is vulnerable to improper session handling of managed servers on Gateway installation

Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration

CVE-2023-4338 9.8 - Critical - August 15, 2023

Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not provide X-Content-Type-Options Headers

Broadcom RAID Controller web interface is vulnerable to exposure of private keys used for CIM stored with insecure file permissions

CVE-2023-4339 7.5 - High - August 15, 2023

Broadcom RAID Controller web interface is vulnerable to exposure of private keys used for CIM stored with insecure file permissions

Broadcom RAID Controller is vulnerable to Privilege escalation by taking advantage of the Session prints in the log file

CVE-2023-4340 9.8 - Critical - August 15, 2023

Broadcom RAID Controller is vulnerable to Privilege escalation by taking advantage of the Session prints in the log file

Broadcom RAID Controller is vulnerable to Privilege escalation to root due to creation of insecure folders by Web GUI

CVE-2023-4341 9.8 - Critical - August 15, 2023

Broadcom RAID Controller is vulnerable to Privilege escalation to root due to creation of insecure folders by Web GUI

Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP strict-transport-security policy

CVE-2023-4342 9.8 - Critical - August 15, 2023

Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP strict-transport-security policy

Broadcom RAID Controller web interface is vulnerable due to exposure of sensitive password information in the URL as a URL search parameter

CVE-2023-4343 7.5 - High - August 15, 2023

Broadcom RAID Controller web interface is vulnerable due to exposure of sensitive password information in the URL as a URL search parameter

Broadcom RAID Controller web interface is vulnerable to insufficient randomness due to improper use of ssl.rnd to setup CIM connection

CVE-2023-4344 9.8 - Critical - August 15, 2023

Broadcom RAID Controller web interface is vulnerable to insufficient randomness due to improper use of ssl.rnd to setup CIM connection

Use of Insufficiently Random Values

Broadcom RAID Controller web interface is vulnerable client-side control bypass leads to unauthorized data access for low privileged user

CVE-2023-4345 6.5 - Medium - August 15, 2023

Broadcom RAID Controller web interface is vulnerable client-side control bypass leads to unauthorized data access for low privileged user

An information disclosure in the web interface of Brocade Fabric OS versions before Brocade Fabric OS v9.2.0 and v9.1.1c, could

CVE-2023-31927 5.3 - Medium - August 02, 2023

An information disclosure in the web interface of Brocade Fabric OS versions before Brocade Fabric OS v9.2.0 and v9.1.1c, could allow a remote unauthenticated attacker to get technical details about the web interface.

System files could be overwritten using the less command in Brocade Fabric OS before Brocade Fabric OS v9.1.1c and v9.2.0.

CVE-2023-31926 7.1 - High - August 02, 2023

System files could be overwritten using the less command in Brocade Fabric OS before Brocade Fabric OS v9.1.1c and v9.2.0.

Improper Initialization

A reflected cross-site scripting (XSS) vulnerability exists in Brocade Webtools PortSetting.html of Brocade Fabric OS version before Brocade Fabric OS v9.2.0

CVE-2023-31928 6.1 - Medium - August 02, 2023

A reflected cross-site scripting (XSS) vulnerability exists in Brocade Webtools PortSetting.html of Brocade Fabric OS version before Brocade Fabric OS v9.2.0 that could allow a remote unauthenticated attacker to execute arbitrary JavaScript code in a target users session with the Brocade Webtools application.

XSS

A buffer overflow vulnerability in diagstatus command in Brocade Fabric OS before Brocade Fabric v9.2.0 and v9.1.1c could

CVE-2023-31431 5.5 - Medium - August 02, 2023

A buffer overflow vulnerability in diagstatus command in Brocade Fabric OS before Brocade Fabric v9.2.0 and v9.1.1c could allow an authenticated user to crash the Brocade Fabric OS switch leading to a denial of service.

Classic Buffer Overflow

A buffer overflow vulnerability in secpolicydelete command in Brocade Fabric OS before Brocade Fabric OS v9.1.1c and v9.2.0 could

CVE-2023-31430 5.5 - Medium - August 02, 2023

A buffer overflow vulnerability in secpolicydelete command in Brocade Fabric OS before Brocade Fabric OS v9.1.1c and v9.2.0 could allow an authenticated privileged user to crash the Brocade Fabric OS switch leading to a denial of service.

Classic Buffer Overflow

Through manipulation of passwords or other variables

CVE-2023-31432 7.8 - High - August 02, 2023

Through manipulation of passwords or other variables, using commands such as portcfgupload, configupload, license, myid, a non-privileged user could obtain root privileges in Brocade Fabric OS versions before Brocade Fabric OS v9.1.1c and v9.2.0.

Improper Privilege Management

Brocade Fabric OS before Brocade Fabric OS v9.1.1c, v9.2.0 contains a vulnerability in the command line

CVE-2023-31428 5.5 - Medium - August 02, 2023

Brocade Fabric OS before Brocade Fabric OS v9.1.1c, v9.2.0 contains a vulnerability in the command line that could allow a local user to dump files under user's home directory using grep.

Unrestricted File Upload

Brocade Fabric OS versions before Brocade Fabric OS v9.1.1c, and v9.2.0 Could

CVE-2023-31427 7.8 - High - August 01, 2023

Brocade Fabric OS versions before Brocade Fabric OS v9.1.1c, and v9.2.0 Could allow an authenticated, local user with knowledge of full path names inside Brocade Fabric OS to execute any command regardless of assigned privilege. Starting with Fabric OS v9.1.0, root account access is disabled.

Directory traversal

The Brocade Fabric OS Commands configupload and configdownload before Brocade Fabric OS v9.1.1c

CVE-2023-31426 6.5 - Medium - August 01, 2023

The Brocade Fabric OS Commands configupload and configdownload before Brocade Fabric OS v9.1.1c, v8.2.3d, v9.2.0 print scp, sftp, ftp servers passwords in supportsave. This could allow a remote authenticated attacker to access sensitive information.

Insertion of Sensitive Information into Log File

Brocade Fabric OS before Brocade Fabric OS 9.1.1c, 9.2.0 contains a vulnerability when using various commands such as chassisdistribute, reboot, rasman, errmoduleshow, errfilterset, hassiscfgperrthreshold, supportshowcfgdisable and supportshowcfgenable commands

CVE-2023-31429 5.5 - Medium - August 01, 2023

Brocade Fabric OS before Brocade Fabric OS 9.1.1c, 9.2.0 contains a vulnerability when using various commands such as chassisdistribute, reboot, rasman, errmoduleshow, errfilterset, hassiscfgperrthreshold, supportshowcfgdisable and supportshowcfgenable commands that can cause the content of shell interpreted variables to be printed in the terminal.

Command Injection

A vulnerability in the fosexec command of Brocade Fabric OS after Brocade Fabric OS v9.1.0 and, before Brocade Fabric OS v9.1.1 could

CVE-2023-31425 7.8 - High - August 01, 2023

A vulnerability in the fosexec command of Brocade Fabric OS after Brocade Fabric OS v9.1.0 and, before Brocade Fabric OS v9.1.1 could allow a local authenticated user to perform privilege escalation to root by breaking the rbash shell. Starting with Fabric OS v9.1.0, root account access is disabled.

Shell injection

Advanced Secure Gateway and Content Analysis

CVE-2023-23955 8.1 - High - June 01, 2023

Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Server-Side Request Forgery vulnerability.

SSRF

Advanced Secure Gateway and Content Analysis

CVE-2023-23954 5.4 - Medium - June 01, 2023

Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Stored Cross-Site Scripting vulnerability.

XSS

Advanced Secure Gateway and Content Analysis

CVE-2023-23953 7.8 - High - June 01, 2023

Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to an Elevation of Privilege vulnerability.

Advanced Secure Gateway and Content Analysis

CVE-2023-23952 9.8 - Critical - June 01, 2023

Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Command Injection vulnerability.

Command Injection

A user can supply malicious HTML and JavaScript code

CVE-2023-23956 5.4 - Medium - May 30, 2023

A user can supply malicious HTML and JavaScript code that will be executed in the client browser

XSS

A path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element

CVE-2023-27534 8.8 - High - March 30, 2023

A path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate a path relative to the user's home directory. Attackers can exploit this flaw to bypass filtering or execute arbitrary code by crafting a path like /~2/foo while accessing a server with a specific user.

Directory traversal

A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles"

CVE-2023-27537 5.9 - Medium - March 30, 2023

A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks, two threads sharing the same HSTS data could end up doing a double-free or use-after-free.

Double-free

An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact

CVE-2023-27538 5.5 - Medium - March 30, 2023

An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the configurations match. However, two SSH settings were omitted from the configuration check, allowing them to match easily, potentially leading to the reuse of an inappropriate connection.

authentification

An issue found in TCPreplay tcprewrite v.4.4.3

CVE-2023-27783 7.5 - High - March 16, 2023

An issue found in TCPreplay tcprewrite v.4.4.3 allows a remote attacker to cause a denial of service via the tcpedit_dlt_cleanup function at plugins/dlt_plugins.c.

assertion failure

An issue found in TCPReplay v.4.4.3

CVE-2023-27784 7.5 - High - March 16, 2023

An issue found in TCPReplay v.4.4.3 allows a remote attacker to cause a denial of service via the read_hexstring function at the utils.c:309 endpoint.

NULL Pointer Dereference

An issue found in TCPprep v.4.4.3

CVE-2023-27789 7.5 - High - March 16, 2023

An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the cidr2cidr function at the cidr.c:178 endpoint.

assertion failure

An issue found in TCPrewrite v.4.4.3

CVE-2023-27788 7.5 - High - March 16, 2023

An issue found in TCPrewrite v.4.4.3 allows a remote attacker to cause a denial of service via the ports2PORT function at the portmap.c:69 endpoint.

assertion failure

An issue found in TCPprep v.4.4.3

CVE-2023-27787 7.5 - High - March 16, 2023

An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the parse_list function at the list.c:81 endpoint.

NULL Pointer Dereference

An issue found in TCPprep v.4.4.3

CVE-2023-27786 7.5 - High - March 16, 2023

An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the macinstring function.

NULL Pointer Dereference

An issue found in TCPreplay TCPprep v.4.4.3

CVE-2023-27785 7.5 - High - March 16, 2023

An issue found in TCPreplay TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the parse endpoints function.

NULL Pointer Dereference

An authenticated user can supply malicious HTML and JavaScript code

CVE-2023-23949 5.4 - Medium - January 26, 2023

An authenticated user can supply malicious HTML and JavaScript code that will be executed in the client browser.

XSS

Ability to enumerate the Oracle LDAP attributes for the current user by modifying the query used by the application

CVE-2023-23951 6.1 - Medium - January 26, 2023

Ability to enumerate the Oracle LDAP attributes for the current user by modifying the query used by the application

XSS

Users supplied input (usually a CRLF sequence)

CVE-2023-23950 6.1 - Medium - January 26, 2023

Users supplied input (usually a CRLF sequence) can be used to split a returning response into two responses.

XSS

Symantec Endpoint Protection, prior to 14.3 RU6 (14.3.9210.6000), may be susceptible to a Elevation of Privilege vulnerability

CVE-2022-25631 7.8 - High - January 20, 2023

Symantec Endpoint Protection, prior to 14.3 RU6 (14.3.9210.6000), may be susceptible to a Elevation of Privilege vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated

Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.