目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1000 CNY

100.0%

Broadcom 厂商漏洞列表 / CVE 中文分析 88

Broadcom 厂商相关 88 条 CVE 漏洞,含 AI 中文分析、POC、CVSS 评分与受影响产品。

博通是全球领先的半导体与基础设施软件供应商,其业务涵盖网络芯片、无线连接技术及企业级软件。历史上,其产品中常见远程代码执行、缓冲区溢出及身份验证绕过等高危漏洞。近期收录的88条CVE多涉及固件与驱动层,部分导致权限提升或信息泄露。作为关键基础设施提供商,其安全更新响应速度及补丁覆盖范围对全球网络稳定性具有重要影响,需持续关注其固件供应链风险。

CVE IDタイトルCVSS深刻度公開日
CVE-2024-36455 Symantec Privileged Access Manager Remote Command Execution vulnerability — Symantec Privileged Access Management 9.8 -2024-07-15
CVE-2024-36459 Cross-Site Scripting Vulnerability in Symantec SiteMinder Web Agent — Symantec SiteMinder 6.1AIMediumAI2024-06-14
CVE-2023-4325 Broadcom RAID Controller web interface is vulnerable due to usage of Libcurl with LSA has known vulnerabilities — LSI Storage Authority (LSA) 9.8 -2023-08-15
CVE-2023-4326 Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that supports obsolete SHA1-based ciphersuites — LSI Storage Authority (LSA)CWE-327 9.1 -2023-08-15
CVE-2023-4324 Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP Content-Security-Policy headers — LSI Storage Authority (LSA) 9.4 -2023-08-15
CVE-2023-4327 Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Linux — LSI Storage Authority (LSA)CWE-522 5.5 -2023-08-15
CVE-2023-4328 Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Linux — LSI Storage Authority (LSA)CWE-522 5.5 -2023-08-15
CVE-2023-4329 Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard SESSIONID cookie with SameSite attribute — LSI Storage Authority (LSA) 8.2 -2023-08-15
CVE-2023-4331 Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that support obsolete and vulnerable TLS protocols — LSI Storage Authority (LSA)CWE-327 9.1 -2023-08-15
CVE-2023-4332 Broadcom RAID Controller web interface is vulnerable due to Improper permissions on the log file — LSI Storage Authority (LSA)CWE-732 7.8 -2023-08-15
CVE-2023-4333 Broadcom RAID Controller web interface doesn’t enforce SSL cipher ordering by server — LSI Storage Authority (LSA)CWE-326 5.5 -2023-08-15
CVE-2023-4334 Broadcom RAID Controller Web server (nginx) is serving private files without any authentication — LSI Storage Authority (LSA) 7.5 -2023-08-15
CVE-2023-4335 Broadcom RAID Controller Web server (nginx) is serving private server-side files without any authentication on Linux — LSI Storage Authority (LSA) 6.2 -2023-08-15
CVE-2023-4336 Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard cookies with Secure attribute — LSI Storage Authority (LSA) 8.2 -2023-08-15
CVE-2023-4337 Broadcom RAID Controller web interface is vulnerable to improper session handling of managed servers on Gateway installation — LSI Storage Authority (LSA) 8.8 -2023-08-15
CVE-2023-4338 Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not provide X-Content-Type-Options Headers — LSI Storage Authority (LSA) 7.6 -2023-08-15
CVE-2023-4341 Broadcom RAID Controller is vulnerable to Privilege escalation to root due to creation of insecure folders by Web GUI — LSI Storage Authority (LSA) 7.8 -2023-08-15
CVE-2023-4340 Broadcom RAID Controller is vulnerable to Privilege escalation by taking advantage of the Session prints in the log file — LSI Storage Authority (LSA) 7.8 -2023-08-15
CVE-2023-4339 Broadcom RAID Controller web interface is vulnerable to exposure of private keys used for CIM stored with insecure file permissions — LSI Storage Authority (LSA) 5.5 -2023-08-15
CVE-2023-4342 Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP strict-transport-security policy — LSI Storage Authority (LSA) 9.8 -2023-08-15
CVE-2023-4343 Broadcom RAID Controller web interface is vulnerable due to exposure of sensitive password information in the URL as a URL search parameter — LSI Storage Authority (LSA) 9.1 -2023-08-15
CVE-2023-4344 Broadcom RAID Controller web interface is vulnerable to insufficient randomness due to improper use of ssl.rnd to setup CIM connection — LSI Storage Authority (LSA)CWE-331 5.3 -2023-08-15
CVE-2023-4323 Broadcom RAID Controller web interface is vulnerable to improper session management of active sessions on Gateway setup — LSI Storage Authority (LSA) 9.8 -2023-08-15
CVE-2023-4345 Broadcom RAID Controller web interface is vulnerable client-side control bypass — LSI Storage Authority (LSA) 7.1 -2023-08-15
CVE-2019-9502 Broadcom wl driver is vulnerable to heap buffer overflow — WiFi driversCWE-122 7.9 High2020-02-03
CVE-2019-9501 Broadcom wl driver is vulnerable to heap buffer overflow — WiFi driversCWE-122 7.9 High2020-02-03
CVE-2019-9503 Broadcom brcmfmac driver is vulnerable to a frame validation bypass — brcmfmac WiFi driverCWE-20 7.9 High2020-01-16
CVE-2019-9500 Broadcom brcmfmac driver is vulnerable to a heap buffer overflow — brcmfmac WiFi driverCWE-122 7.9 High2020-01-16

本页汇总了 Broadcom 厂商截至目前公开的全部 88 条 CVE 漏洞。每条漏洞均包含 CVSS 评分、CWE 弱点分类、受影响产品与参考链接,并附带 AI 生成的中文分析以便快速判断风险。