Vulnerabilidades em Broadcom

93 resultados
Análise Vexday

Com 91 CVEs catalogadas, o portfólio da Broadcom apresenta uma taxa de exploração ativa abaixo da média geral do catálogo, sem registros no CISA KEV e sem provas de conceito públicas conhecidas — indicadores que sugerem um nível de pressão ofensiva relativamente contido no momento. Das seis vulnerabilidades de severidade crítica, nenhuma figura em exploração confirmada, embora a ausência de PoC pública não elimine o risco de exploração privada. O tipo de falha mais recorrente é CWE-269 (gerenciamento impróprio de privilégios), o que aponta para uma superfície de ataque concentrada em escalonamento de privilégios e controle de acesso — área que merece atenção especial em ambientes com múltiplos níveis de permissão. A CVE mais perigosa atualmente identificada, CVE-2019-9500, apresenta EPSS de 0,0384, valor modesto, mas sua antiguidade sugere que sistemas sem as devidas correções acumuladas permanecem expostos a um vetor conhecido há anos.

CVE-2023-4338Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not provide X-Content-Type-Options HeadersEPSS 0.6%CVE-2023-4329Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard SESSIONID cookie with SameSite attributeEPSS 0.6%CVE-2023-4337Broadcom RAID Controller web interface is vulnerable to improper session handling of managed servers on Gateway installationEPSS 0.6%CVE-2023-4342Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP strict-transport-security policyEPSS 0.6%CVE-2023-4324Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP Content-Security-Policy headersEPSS 0.6%CVE-2023-4325Broadcom RAID Controller web interface is vulnerable due to usage of Libcurl with LSA has known vulnerabilitiesEPSS 0.6%CVE-2025-4971HIGHBroadcom Automic Automation Agent Unix privilege escalationEPSS 0.5%CVE-2023-4334Broadcom RAID Controller Web server (nginx) is serving private files without any authenticationEPSS 0.5%CVE-2023-4332Broadcom RAID Controller web interface is vulnerable due to Improper permissions on the log fileEPSS 0.5%CVE-2023-4335Broadcom RAID Controller Web server (nginx) is serving private server-side files without any authentication on LinuxEPSS 0.5%CVE-2023-4343Broadcom RAID Controller web interface is vulnerable due to exposure of sensitive password information in the URL as a URL search parameterEPSS 0.5%CVE-2023-4345Broadcom RAID Controller web interface is vulnerable client-side control bypassEPSS 0.5%CVE-2024-36455CRITICALSymantec Privileged Access Manager Remote Command Execution vulnerabilityEPSS 0.5%CVE-2025-10847HIGHDX UIM Probe Improper ACL Handling RCEEPSS 0.4%CVE-2024-36459HIGHCross-Site Scripting Vulnerability in Symantec SiteMinder Web AgentEPSS 0.4%CVE-2023-4326Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that supports obsolete SHA1-based ciphersuitesEPSS 0.3%CVE-2026-11815MEDIUMInsecure Deserialization via MITM in Layer 7 Policy ManagerEPSS 0.3%CVE-2025-69273HIGHSpectrum broken authenticationEPSS 0.3%CVE-2025-8660MEDIUMPrivilege Escalation in Symantec PGP Encryption 11.0.1EPSS 0.3%CVE-2024-38493MEDIUMSymantec Privileged Access Manager Reflected Cross Site Scripting vulnerabilityEPSS 0.3%