VendorsBroadcomraid_controller_web_interfaceall versions
Vulnerabilities

Broadcom RAID Controller Web Interface

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

22CVEs
CVE-2023-4323
Broadcom RAID Controller web interface is vulnerable to improper session management of active sessions on Gateway setup
Published 2023-08-15 · Modified
9.8EPSS 0.007
CVE-2023-4324
Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP Content-Security-Policy headers
Published 2023-08-15 · Modified
9.8EPSS 0.007
CVE-2023-4325
Broadcom RAID Controller web interface is vulnerable due to usage of Libcurl with LSA has known vulnerabilities
Published 2023-08-15 · Modified
9.8EPSS 0.007
CVE-2023-4344
Broadcom RAID Controller web interface is vulnerable to insufficient randomness due to improper use of ssl.rnd to setup CIM connection
Published 2023-08-15 · Modified
9.8EPSS 0.007
CVE-2023-4342
Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP strict-transport-security policy
Published 2023-08-15 · Modified
9.8EPSS 0.007
CVE-2023-4341
Broadcom RAID Controller is vulnerable to Privilege escalation to root due to creation of insecure folders by Web GUI
Published 2023-08-15 · Modified
9.8EPSS 0.007
CVE-2023-4329
Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard SESSIONID cookie with SameSite attribute
Published 2023-08-15 · Modified
9.8EPSS 0.007
CVE-2023-4340
Broadcom RAID Controller is vulnerable to Privilege escalation by taking advantage of the Session prints in the log file
Published 2023-08-15 · Modified
9.8EPSS 0.007
CVE-2023-4336
Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard cookies with Secure attribute
Published 2023-08-15 · Modified
9.8EPSS 0.007
CVE-2023-4337
Broadcom RAID Controller web interface is vulnerable to improper session handling of managed servers on Gateway installation
Published 2023-08-15 · Modified
9.8EPSS 0.007
CVE-2023-4338
Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not provide X-Content-Type-Options Headers
Published 2023-08-15 · Modified
9.8EPSS 0.007
CVE-2023-4339
Broadcom RAID Controller web interface is vulnerable to exposure of private keys used for CIM stored with insecure file permissions
Published 2023-08-15 · Modified
7.5EPSS 0.008
CVE-2023-4334
Broadcom RAID Controller Web server (nginx) is serving private files without any authentication
Published 2023-08-15 · Modified
7.5EPSS 0.006
CVE-2023-4332
Broadcom RAID Controller web interface is vulnerable due to Improper permissions on the log file
Published 2023-08-15 · Modified
7.5EPSS 0.006
CVE-2023-4335
Broadcom RAID Controller Web server (nginx) is serving private server-side files without any authentication on Linux
Published 2023-08-15 · Modified
7.5EPSS 0.006
CVE-2023-4343
Broadcom RAID Controller web interface is vulnerable due to exposure of sensitive password information in the URL as a URL search parameter
Published 2023-08-15 · Modified
7.5EPSS 0.006
CVE-2023-4326
Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that supports obsolete SHA1-based ciphersuites
Published 2023-08-15 · Modified
7.5EPSS 0.004
CVE-2023-4331
Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that support obsolete and vulnerable TLS protocols
Published 2023-08-15 · Modified
7.5EPSS 0.004
CVE-2023-4345
Broadcom RAID Controller web interface is vulnerable client-side control bypass
Published 2023-08-15 · Modified
6.5EPSS 0.006
CVE-2023-4333
Broadcom RAID Controller web interface doesn’t enforce SSL cipher ordering by server
Published 2023-08-15 · Modified
5.5EPSS 0.001
CVE-2023-4328
Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Linux
Published 2023-08-15 · Modified
5.5EPSS 0.001
CVE-2023-4327
Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Linux
Published 2023-08-15 · Modified
5.5EPSS 0.001