📦

raid_controller_web_interface

Vendor: broadcom

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 0 Remote Access
Total CVEs 22 Total Indexed
Avg. EPSS 0.48% Exploit Prob.
Latest CVE CVE-2023-4344 Aug 15

Security Vulnerability Index

Page 1 / 3
9.8 CVSS

Broadcom RAID Controller web interface is vulnerable to insufficient randomness due to improper use of ssl.rnd to setup CIM connection

EPSS: 0.59%
7.5 CVSS

Broadcom RAID Controller web interface is vulnerable due to exposure of sensitive password information in the URL as a URL search parameter

EPSS: 0.48%
9.8 CVSS

Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP strict-transport-security policy

EPSS: 0.59%
9.8 CVSS

Broadcom RAID Controller is vulnerable to Privilege escalation to root due to creation of insecure folders by Web GUI

EPSS: 0.59%
9.8 CVSS

Broadcom RAID Controller is vulnerable to Privilege escalation by taking advantage of the Session prints in the log file

EPSS: 0.59%
7.5 CVSS

Broadcom RAID Controller web interface is vulnerable to exposure of private keys used for CIM stored with insecure file permissions

EPSS: 0.69%
9.8 CVSS

Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not provide X-Content-Type-Options Headers

EPSS: 0.59%
9.8 CVSS

Broadcom RAID Controller web interface is vulnerable to improper session handling of managed servers on Gateway installation

EPSS: 0.59%
9.8 CVSS

Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard cookies with Secure attribute

EPSS: 0.59%
7.5 CVSS

Broadcom RAID Controller Web server (nginx) is serving private server-side files without any authentication on Linux

EPSS: 0.49%