Vulnerabilities > Broadcom

DATE CVE VULNERABILITY TITLE RISK
2021-08-12 CVE-2021-27794 Improper Authentication vulnerability in Broadcom Fabric Operating System
A vulnerability in the authentication mechanism of Brocade Fabric OS versions before Brocade Fabric OS v.9.0.1a, v8.2.3a and v7.4.2h could allow a user to Login with empty password, and invalid password through telnet, ssh and REST.
local
low complexity
broadcom CWE-287
7.8
2021-07-14 CVE-2021-34174 Unspecified vulnerability in Broadcom Bcm4352 Firmware and Bcm43684 Firmware
A vulnerability exists in Broadcom BCM4352 and BCM43684 chips.
low complexity
broadcom
4.6
2021-06-30 CVE-2021-30648 Improper Authentication vulnerability in Broadcom products
The Symantec Advanced Secure Gateway (ASG) and ProxySG web management consoles are susceptible to an authentication bypass vulnerability.
network
low complexity
broadcom CWE-287
critical
9.8
2021-06-09 CVE-2020-15377 Server-Side Request Forgery (SSRF) vulnerability in Broadcom Sannav 2.1.0
Webtools in Brocade SANnav before version 2.1.1 allows unauthenticated users to make requests to arbitrary hosts due to a misconfiguration; this is commonly referred to as Server-Side Request Forgery (SSRF).
network
low complexity
broadcom CWE-918
critical
9.8
2021-06-09 CVE-2020-15378 Unspecified vulnerability in Broadcom Sannav 2.1.0
The OVA version of Brocade SANnav before version 2.1.1 installation with IPv6 networking exposes the docker container ports to the network, increasing the potential attack surface.
network
low complexity
broadcom
5.3
2021-06-09 CVE-2020-15379 Improper Input Validation vulnerability in Broadcom Brocade Sannav 1.1.0/1.1.1/2.0
Brocade SANnav before v.2.1.0a could allow remote attackers cause a denial-of-service condition due to a lack of proper validation, of the length of user-supplied data as name for custom field name.
network
low complexity
broadcom CWE-20
7.5
2021-06-09 CVE-2020-15380 Information Exposure Through Log Files vulnerability in Broadcom Sannav 2.1.0
Brocade SANnav before version 2.1.1 logs account credentials at the ‘trace’ logging level.
network
low complexity
broadcom CWE-532
7.5
2021-06-09 CVE-2020-15384 Cleartext Storage of Sensitive Information vulnerability in Broadcom Sannav 2.1.0
Brocade SANNav before version 2.1.1 contains an information disclosure vulnerability.
network
low complexity
broadcom CWE-312
5.3
2021-06-09 CVE-2020-15385 Unspecified vulnerability in Broadcom Sannav 2.1.0
Brocade SANnav before version 2.1.1 allows an authenticated attacker to list directories, and list files without permission.
network
low complexity
broadcom
5.4
2021-06-09 CVE-2020-15386 Unspecified vulnerability in Broadcom Fabric Operating System
Brocade Fabric OS prior to v9.0.1a and 8.2.3a and after v9.0.0 and 8.2.2d may observe high CPU load during security scanning, which could lead to a slower response to CLI commands and other operations.
network
low complexity
broadcom
5.3