Vulnerabilities > Broadcom > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-07-09 CVE-2024-3596 Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in multiple products
RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.
network
high complexity
freeradius broadcom sonicwall CWE-924
critical
9.0
2024-04-25 CVE-2024-4173 Unspecified vulnerability in Broadcom Brocade Sannav
A vulnerability in Brocade SANnav exposes Kafka in the wan interface. The vulnerability could allow an unauthenticated attacker to perform various attacks, including DOS against the Brocade SANnav.
network
low complexity
broadcom
critical
9.8
2024-04-19 CVE-2024-29966 Use of Hard-coded Credentials vulnerability in Broadcom Brocade Sannav
Brocade SANnav OVA before v2.3.1 and v2.3.0a contain hard-coded credentials in the documentation that appear as the appliance's root password.
network
low complexity
broadcom CWE-798
critical
9.8
2024-04-04 CVE-2023-3454 OS Command Injection vulnerability in Broadcom Fabric Operating System
Remote code execution (RCE) vulnerability in Brocade Fabric OS after v9.0 and before v9.2.0 could allow an attacker to execute arbitrary code and use this to gain root access to the Brocade switch.
network
low complexity
broadcom CWE-78
critical
9.8
2024-01-26 CVE-2024-23613 Classic Buffer Overflow vulnerability in Broadcom Symantec Deployment Solutions 7.9
A buffer overflow vulnerability exists in Symantec Deployment Solution version 7.9 when parsing UpdateComputer tokens.
network
low complexity
broadcom CWE-120
critical
9.8
2024-01-26 CVE-2024-23614 Classic Buffer Overflow vulnerability in Broadcom Symantec Messaging Gateway 9.5
A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 9.5 and before.
network
low complexity
broadcom CWE-120
critical
9.8
2024-01-26 CVE-2024-23615 Classic Buffer Overflow vulnerability in Broadcom Symantec Messaging Gateway 10.5/9.5
A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 10.5 and before.
network
low complexity
broadcom CWE-120
critical
9.8
2024-01-26 CVE-2024-23616 Classic Buffer Overflow vulnerability in Broadcom Symantec Server Management Suite 7.9
A buffer overflow vulnerability exists in Symantec Server Management Suite version 7.9 and before.
network
low complexity
broadcom CWE-120
critical
9.8
2023-08-31 CVE-2023-31424 Unspecified vulnerability in Broadcom Brocade Sannav
Brocade SANnav Web interface before Brocade SANnav v2.3.0 and v2.2.2a allows remote unauthenticated users to bypass web authentication and authorization.
network
low complexity
broadcom
critical
9.8
2023-08-15 CVE-2023-4323 Unspecified vulnerability in Broadcom Raid Controller web Interface 51.12.02779
Broadcom RAID Controller web interface is vulnerable to improper session management of active sessions on Gateway setup
network
low complexity
broadcom
critical
9.8