Broadcom
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Broadcom product.
RSS Feeds for Broadcom security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Broadcom products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Broadcom Sorted by Most Security Vulnerabilities since 2018
Known Exploited Broadcom Vulnerabilities
The following Broadcom vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
Title | Description | Added |
---|---|---|
Broadcom Brocade Fabric OS Code Injection Vulnerability |
Broadcom Brocade Fabric OS contains a code injection vulnerability that allows a local user with administrative privileges to execute arbitrary code with full root privileges. CVE-2025-1976 Exploit Probability: 2.1% |
April 28, 2025 |
By the Year
In 2025 there have been 2 vulnerabilities in Broadcom with an average score of 7.1 out of ten. Last year, in 2024 Broadcom had 43 security vulnerabilities published. Right now, Broadcom is on track to have less security vulnerabilities in 2025 than it did last year. However, the average CVE base score of the vulnerabilities in 2025 is greater by 0.11.
Year | Vulnerabilities | Average Score |
---|---|---|
2025 | 2 | 7.10 |
2024 | 43 | 6.99 |
2023 | 59 | 7.33 |
2022 | 62 | 7.48 |
2021 | 45 | 6.84 |
2020 | 47 | 7.32 |
2019 | 33 | 7.38 |
2018 | 44 | 7.52 |
It may take a day or so for new Broadcom vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Broadcom Security Vulnerabilities
Symantec Endpoint Protection Windows Agent, running an ERASER Engine prior to 119.1.7.8, may be susceptible to an Elevation of Privilege vulnerability, which may allow an attacker to delete resources
CVE-2025-3599
7.5 - High
- April 30, 2025
Symantec Endpoint Protection Windows Agent, running an ERASER Engine prior to 119.1.7.8, may be susceptible to an Elevation of Privilege vulnerability, which may allow an attacker to delete resources that are normally protected from an application or user.
Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege
CVE-2025-1976
6.7 - Medium
- April 24, 2025
Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can potentially execute arbitrary code with full root privileges on Fabric OS versions 9.1.0 through 9.1.1d6.
Shell injection
Brocade Fabric OS SFTP/FTP Server Password Exposure in Core Dump
CVE-2024-10403
7.5 - High
- November 21, 2024
Brocade Fabric OS versions before 8.2.3e2, versions 9.0.0 through 9.2.0c, and 9.2.1 through 9.2.1a can capture the SFTP/FTP server password used for a firmware download operation initiated by SANnav or through WebEM in a weblinker core dump that is later captured via supportsave.
Files or Directories Accessible to External Parties
Brocade SANnav: Information Exposure via Debug Logs
CVE-2022-43937
5.5 - Medium
- November 21, 2024
Possible information exposure through log file vulnerability where sensitive fields are recorded in the debug-enabled logs when debugging is turned on in Brocade SANnav before 2.3.0 and 2.2.2a
Insertion of Sensitive Information into Log File
Brocade SANnav Password Logging Vulnerability in Brocade Fabric OS
CVE-2022-43936
4.9 - Medium
- November 21, 2024
Brocade SANnav versions before 2.2.2 log Brocade Fabric OS switch passwords when debugging is enabled.
Insertion of Sensitive Information into Log File
Brocade SANnav Information Exposure through Log Files
CVE-2022-43935
4.4 - Medium
- November 21, 2024
An information exposure through log file vulnerability exists in Brocade SANnav before Brocade SANnav 2.2.2, where Brocade Fabric OS Switch passwords and authorization IDs are printed in the embedded MLS DB file.
Insertion of Sensitive Information into Log File
Brocade SANnav Weak Key Exchange Algorithm Vulnerability
CVE-2022-43934
7.5 - High
- November 21, 2024
Brocade SANnav before Brocade SANnav 2.2.2 supports key exchange algorithms, which are considered weak on ports 24, 6514, 18023, 19094, and 19095.
Use of a Broken or Risky Cryptographic Algorithm
Brocade SANnav Information Exposure Through Log Files
CVE-2022-43933
4.4 - Medium
- November 21, 2024
An information exposure through log file vulnerability exists in Brocade SANnav before Brocade SANnav 2.2.2, where configuration secrets are logged in supportsave. Supportsave file is generated by an admin user troubleshooting the switch. The Logged information may include usernames and passwords, and secret keys.
Insertion of Sensitive Information into Log File
A vulnerability in Brocade Fabric OS versions before 9.2.2 could allow man-in-the-middle attackers to conduct remote Service Session Hijacking
CVE-2024-7516
7.1 - High
- November 12, 2024
A vulnerability in Brocade Fabric OS versions before 9.2.2 could allow man-in-the-middle attackers to conduct remote Service Session Hijacking that may arise from the attacker's ability to forge an SSH key while the Brocade Fabric OS Switch is performing various remote operations initiated by a switch admin.
Missing Authentication for Critical Function
A reflected cross-site scripting (XSS) vulnerability exists in the PAM UI web interface
CVE-2024-38493
6.1 - Medium
- July 15, 2024
A reflected cross-site scripting (XSS) vulnerability exists in the PAM UI web interface. A remote attacker able to convince a PAM user to click on a specially crafted link to the PAM UI web interface could potentially execute arbitrary client-side code in the context of PAM UI.
XSS
RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who
CVE-2024-3596
9 - Critical
- July 09, 2024
RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.
Improper Validation of Integrity Check Value
A vulnerability in a password management API in Brocade Fabric OS versions before v9.2.1
CVE-2024-29954
5.5 - Medium
- June 26, 2024
A vulnerability in a password management API in Brocade Fabric OS versions before v9.2.1, v9.2.0b, v9.1.1d, and v8.2.3e prints sensitive information in log files. This could allow an authenticated user to view the server passwords for protocols such as scp and sftp. Detail. When the firmwaredownload command is incorrectly entered or points to an erroneous file, the firmware download log captures the failed command, including any password entered in the command line.
Insertion of Sensitive Information into Log File
A vulnerability in the default configuration of the Simple Network
Management Protocol (SNMP) feature of Brocade Fabric OS versions before
v9.0.0 could
CVE-2024-5460
8.1 - High
- June 26, 2024
A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Brocade Fabric OS versions before v9.0.0 could allow an authenticated, remote attacker to read data from an affected device via SNMP. The vulnerability is due to hard-coded, default community string in the configuration file for the SNMP daemon. An attacker could exploit this vulnerability by using the static community string in SNMP version 1 queries to an affected device.
Use of Hard-coded Credentials
A vulnerability in the web interface in Brocade Fabric OS before v9.2.1
CVE-2024-29953
4.3 - Medium
- June 26, 2024
A vulnerability in the web interface in Brocade Fabric OS before v9.2.1, v9.2.0b, and v9.1.1d prints encoded session passwords on session storage for Virtual Fabric platforms. This could allow an authenticated user to view other users' session encoded passwords.
Insecure Storage of Sensitive Information
The PostgreSQL implementation in Brocade SANnav versions before 2.3.0a is vulnerable to an incorrect local authentication flaw
CVE-2024-2860
7.8 - High
- May 08, 2024
The PostgreSQL implementation in Brocade SANnav versions before 2.3.0a is vulnerable to an incorrect local authentication flaw. An attacker accessing the VM where the Brocade SANnav is installed can gain access to sensitive data inside the PostgreSQL database.
Missing Authentication for Critical Function
A vulnerability in Brocade SANnav exposes Kafka in the wan interface
CVE-2024-4173
9.8 - Critical
- April 25, 2024
A vulnerability in Brocade SANnav exposes Kafka in the wan interface. The vulnerability could allow an unauthenticated attacker to perform various attacks, including DOS against the Brocade SANnav.
Brocade SANnav before v2.3.0a lacks protection mechanisms on port 2377/TCP and 7946/TCP, which could
CVE-2024-4159
5.3 - Medium
- April 25, 2024
Brocade SANnav before v2.3.0a lacks protection mechanisms on port 2377/TCP and 7946/TCP, which could allow an unauthenticated attacker to sniff the SANnav Docker information.
In Brocade SANnav, before Brocade SANnav v2.3.0, syslog traffic received
clear text
CVE-2024-4161
7.5 - High
- April 25, 2024
In Brocade SANnav, before Brocade SANnav v2.3.0, syslog traffic received clear text. This could allow an unauthenticated, remote attacker to capture sensitive information.
Cleartext Transmission of Sensitive Information
When a Brocade SANnav installation is upgraded
CVE-2024-29969
7.5 - High
- April 19, 2024
When a Brocade SANnav installation is upgraded from Brocade SANnav v2.2.2 to Brocade SANnav 2.3.0, TLS/SSL weak message authentication code ciphers are added by default for port 18082.
Inadequate Encryption Strength
An information disclosure vulnerability exists in Brocade SANnav before v2.3.1 and v2.3.0a when Brocade SANnav instances are configured in disaster recovery mode
CVE-2024-29968
6.5 - Medium
- April 19, 2024
An information disclosure vulnerability exists in Brocade SANnav before v2.3.1 and v2.3.0a when Brocade SANnav instances are configured in disaster recovery mode. SQL Table names, column names, and SQL queries are collected in DR standby Supportsave. This could allow authenticated users to access the database structure and its contents.
Insecure Storage of Sensitive Information
In Brocade SANnav before Brocade SANnav v2.31 and v2.3.0a, it was observed
CVE-2024-29967
6 - Medium
- April 19, 2024
In Brocade SANnav before Brocade SANnav v2.31 and v2.3.0a, it was observed that Docker instances inside the appliance have insecure mount points, allowing reading and writing access to sensitive files. The vulnerability could allow a sudo privileged user on the host OS to read and write access to these files.
Incorrect Default Permissions
Brocade SANnav OVA before v2.3.1 and v2.3.0a contain hard-coded credentials in the documentation
CVE-2024-29966
9.8 - Critical
- April 19, 2024
Brocade SANnav OVA before v2.3.1 and v2.3.0a contain hard-coded credentials in the documentation that appear as the appliance's root password. The vulnerability could allow an unauthenticated attacker full access to the Brocade SANnav appliance.
Use of Hard-coded Credentials
In Brocade SANnav before v2.3.1, and v2.3.0a, it is possible to back up the appliance
CVE-2024-29965
5.9 - Medium
- April 19, 2024
In Brocade SANnav before v2.3.1, and v2.3.0a, it is possible to back up the appliance from the web interface or the command line interface ("SSH"). The resulting backups are world-readable. A local attacker can recover backup files, restore them to a new malicious appliance, and retrieve the passwords of all the switches.
Insecure Storage of Sensitive Information
Brocade SANnav versions before v2.3.0a do not correctly set permissions on files, including docker files
CVE-2024-29964
6.5 - Medium
- April 19, 2024
Brocade SANnav versions before v2.3.0a do not correctly set permissions on files, including docker files. An unprivileged attacker who gains access to the server can read sensitive information from these files.
Incorrect Permission Assignment for Critical Resource
Brocade SANnav OVA before v2.3.1 and v2.3.0a have an insecure file permission setting that makes files world-readable
CVE-2024-29962
5.5 - Medium
- April 19, 2024
Brocade SANnav OVA before v2.3.1 and v2.3.0a have an insecure file permission setting that makes files world-readable. This could allow a local user without the required privileges to access sensitive information or a Java binary.
Incorrect Default Permissions
Brocade SANnav OVA before v2.3.1, and v2.3.0a, contain hardcoded TLS keys used by Docker
CVE-2024-29963
3.8 - Low
- April 19, 2024
Brocade SANnav OVA before v2.3.1, and v2.3.0a, contain hardcoded TLS keys used by Docker. Note: Brocade SANnav doesn't have access to remote Docker registries.
Use of Hard-coded Credentials
A vulnerability affects Brocade SANnav before v2.3.1 and v2.3.0a
CVE-2024-29961
8.2 - High
- April 19, 2024
A vulnerability affects Brocade SANnav before v2.3.1 and v2.3.0a. It allows a Brocade SANnav service to send ping commands in the background at regular intervals to gridgain.com to check if updates are available for the Component. This could make an unauthenticated, remote attacker aware of the behavior and launch a supply-chain attack against a Brocade SANnav appliance.
In Brocade SANnav server before v2.3.1 and v2.3.0a
CVE-2024-29960
7.5 - High
- April 19, 2024
In Brocade SANnav server before v2.3.1 and v2.3.0a, the SSH keys inside the OVA image are identical in the VM every time SANnav is installed. Any Brocade SAnnav VM based on the official OVA images is vulnerable to MITM over SSH. An attacker can decrypt and compromise the SSH traffic to the SANnav.
Use of Hard-coded Credentials
A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints Brocade Fabric OS switch encrypted passwords in the Brocade SANnav Standby node's support save.
CVE-2024-29959
8.6 - High
- April 19, 2024
A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints Brocade Fabric OS switch encrypted passwords in the Brocade SANnav Standby node's support save.
Insertion of Sensitive Information into Log File
A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints the encryption key in the console when a privileged user executes the script to replace the Brocade SANnav Management Portal standby node
CVE-2024-29958
6.5 - Medium
- April 19, 2024
A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints the encryption key in the console when a privileged user executes the script to replace the Brocade SANnav Management Portal standby node. This could provide attackers an additional, less protected path to acquiring the encryption key.
Insertion of Sensitive Information into Log File
When Brocade SANnav before v2.3.1 and v2.3.0a servers are configured in Disaster Recovery mode
CVE-2024-29957
7.5 - High
- April 19, 2024
When Brocade SANnav before v2.3.1 and v2.3.0a servers are configured in Disaster Recovery mode, the encryption key is stored in the DR log files. This could provide attackers with an additional, less-protected path to acquiring the encryption key.
Insertion of Sensitive Information into Log File
A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints the Brocade SANnav password in clear text in supportsave logs when a user schedules a switch Supportsave
CVE-2024-29956
6.5 - Medium
- April 18, 2024
A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints the Brocade SANnav password in clear text in supportsave logs when a user schedules a switch Supportsave from Brocade SANnav.
Cleartext Storage of Sensitive Information
A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could
CVE-2024-29952
5.5 - Medium
- April 17, 2024
A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow an authenticated user to print the Auth, Priv, and SSL key store passwords in unencrypted logs by manipulating command variables.
Cleartext Storage of Sensitive Information
A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could
CVE-2024-29955
5.5 - Medium
- April 17, 2024
A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow a privileged user to print the SANnav encrypted key in PostgreSQL startup logs. This could provide attackers with an additional, less-protected path to acquiring the encryption key.
Insertion of Sensitive Information into Log File
Brocade SANnav before v2.3.1 and v2.3.0a uses the SHA-1 hash in internal SSH ports
CVE-2024-29951
5.7 - Medium
- April 17, 2024
Brocade SANnav before v2.3.1 and v2.3.0a uses the SHA-1 hash in internal SSH ports that are not open to remote connection.
Inadequate Encryption Strength
The class FileTransfer implemented in Brocade SANnav before v2.3.1, v2.3.0a, uses the ssh-rsa signature scheme, which has a SHA-1 hash
CVE-2024-29950
5.9 - Medium
- April 17, 2024
The class FileTransfer implemented in Brocade SANnav before v2.3.1, v2.3.0a, uses the ssh-rsa signature scheme, which has a SHA-1 hash. The vulnerability could allow a remote, unauthenticated attacker to perform a man-in-the-middle attack.
Inadequate Encryption Strength
Brocade
Web Interface in Brocade Fabric OS v9.x and before v9.2.0 does not
properly represent the portName to the user if the portName contains
reserved characters
CVE-2023-5973
4.3 - Medium
- April 05, 2024
Brocade Web Interface in Brocade Fabric OS v9.x and before v9.2.0 does not properly represent the portName to the user if the portName contains reserved characters. This could allow an authenticated user to alter the UI of the Brocade Switch and change ports display.
Origin Validation Error
Remote code execution (RCE) vulnerability in Brocade Fabric OS after v9.0 and before v9.2.0 could
CVE-2023-3454
9.8 - Critical
- April 04, 2024
Remote code execution (RCE) vulnerability in Brocade Fabric OS after v9.0 and before v9.2.0 could allow an attacker to execute arbitrary code and use this to gain root access to the Brocade switch.
Shell injection
A vulnerability was found in appneta tcpreplay up to 4.4.4
CVE-2024-3024
7.8 - High
- March 28, 2024
A vulnerability was found in appneta tcpreplay up to 4.4.4. It has been classified as problematic. This affects the function get_layer4_v6 of the file /tcpreplay/src/common/get.c. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The identifier VDB-258333 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Memory Corruption
Null Pointer Dereference in mask_cidr6 component at cidr.c in Tcpreplay 4.4.4
CVE-2023-43279
- March 12, 2024
Null Pointer Dereference in mask_cidr6 component at cidr.c in Tcpreplay 4.4.4 allows attackers to crash the application via crafted tcprewrite command.
A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 9.5 and before
CVE-2024-23614
9.8 - Critical
- January 26, 2024
A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 9.5 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as root.
Classic Buffer Overflow
A buffer overflow vulnerability exists in Symantec Server Management Suite version 7.9 and before
CVE-2024-23616
9.8 - Critical
- January 26, 2024
A buffer overflow vulnerability exists in Symantec Server Management Suite version 7.9 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as SYSTEM.
Classic Buffer Overflow
A buffer overflow vulnerability exists in Symantec Deployment Solution version 7.9 when parsing UpdateComputer tokens
CVE-2024-23613
9.8 - Critical
- January 26, 2024
A buffer overflow vulnerability exists in Symantec Deployment Solution version 7.9 when parsing UpdateComputer tokens. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as SYSTEM.
Classic Buffer Overflow
A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 10.5 and before
CVE-2024-23615
9.8 - Critical
- January 26, 2024
A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 10.5 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as root.
Classic Buffer Overflow
A buffer overflow vulnerability exists in Symantec Data Loss Prevention version 14.0.2 and before
CVE-2024-23617
8.8 - High
- January 26, 2024
A buffer overflow vulnerability exists in Symantec Data Loss Prevention version 14.0.2 and before. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a crafted document to achieve code execution.
Classic Buffer Overflow
Within tcpreplay's tcprewrite
CVE-2023-4256
5.5 - Medium
- December 21, 2023
Within tcpreplay's tcprewrite, a double free vulnerability has been identified in the tcpedit_dlt_cleanup() function within plugins/dlt_plugins.c. This vulnerability can be exploited by supplying a specifically crafted file to the tcprewrite binary. This flaw enables a local attacker to initiate a Denial of Service (DoS) attack.
Double-free
Jaspersoft Clarity PPM version 14.3.0.298 was discovered to contain an arbitrary file upload vulnerability
CVE-2023-37790
5.4 - Medium
- November 09, 2023
Jaspersoft Clarity PPM version 14.3.0.298 was discovered to contain an arbitrary file upload vulnerability via the Profile Picture Upload function.
XSS
Brocade
SANnav before v2.3.0 and v2.2.2a stores SNMPv3 Authentication passwords
in plaintext
CVE-2023-31925
6.5 - Medium
- August 31, 2023
Brocade SANnav before v2.3.0 and v2.2.2a stores SNMPv3 Authentication passwords in plaintext. A privileged user could retrieve these credentials with knowledge and access to these log files. SNMP credentials could be seen in SANnav SupportSave if the capture is performed after an SNMP configuration failure causes an SNMP communication log dump.
Cleartext Storage of Sensitive Information
In
Brocade Fabric OS before v9.2.0a, a local authenticated privileged user
CVE-2023-4163
4.4 - Medium
- August 31, 2023
In Brocade Fabric OS before v9.2.0a, a local authenticated privileged user can trigger a buffer overflow condition, leading to a kernel panic with large input to buffers in the portcfgfportbuffers command.
Classic Buffer Overflow