Vulnerabilities > Broadcom > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-06-01 CVE-2023-23952 Command Injection vulnerability in Broadcom Advanced Secure Gateway and Content Analysis
Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Command Injection vulnerability.
network
low complexity
broadcom CWE-77
critical
9.8
2022-12-01 CVE-2022-37016 Unspecified vulnerability in Broadcom Symantec Endpoint Protection
Symantec Endpoint Protection (Windows) agent may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.
network
low complexity
broadcom
critical
9.8
2022-07-07 CVE-2021-46825 HTTP Request Smuggling vulnerability in Broadcom Advanced Secure Gateway and Proxysg
Symantec Advanced Secure Gateway (ASG) and ProxySG are susceptible to an HTTP desync vulnerability.
network
low complexity
broadcom CWE-444
critical
9.1
2022-06-21 CVE-2022-2068 OS Command Injection vulnerability in multiple products
In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review.
network
low complexity
openssl debian fedoraproject siemens netapp broadcom CWE-78
critical
9.8
2022-06-16 CVE-2022-33750 Improper Authentication vulnerability in Broadcom CA Automic Automation 12.2/12.3
CA Automic Automation 12.2 and 12.3 contain an authentication error vulnerability in the Automic agent that could allow a remote attacker to potentially execute arbitrary commands.
network
low complexity
broadcom CWE-287
critical
9.8
2022-06-16 CVE-2022-33752 Improper Input Validation vulnerability in Broadcom CA Automic Automation 12.2/12.3
CA Automic Automation 12.2 and 12.3 contain an insufficient input validation vulnerability in the Automic agent that could allow a remote attacker to potentially execute arbitrary code.
network
low complexity
broadcom CWE-20
critical
9.8
2022-06-16 CVE-2022-33754 Improper Input Validation vulnerability in Broadcom CA Automic Automation 12.2/12.3
CA Automic Automation 12.2 and 12.3 contain an insufficient input validation vulnerability in the Automic agent that could allow a remote attacker to potentially execute arbitrary code.
network
low complexity
broadcom CWE-20
critical
9.8
2022-05-06 CVE-2022-28163 SQL Injection vulnerability in Broadcom Sannav 2.1.0/2.1.1/2.1.1.8
In Brocade SANnav before Brocade SANnav 2.2.0, multiple endpoints associated with Zone management are susceptible to SQL injection, allowing an attacker to run arbitrary SQL commands.
network
low complexity
broadcom CWE-89
critical
9.8
2022-02-21 CVE-2021-27797 Use of Hard-coded Credentials vulnerability in Broadcom Fabric Operating System
Brocade Fabric OS before Brocade Fabric OS v8.2.1c, v8.1.2h, and all versions of Brocade Fabric OS v8.0.x and v7.x contain documented hard-coded credentials, which could allow attackers to gain access to the system.
network
low complexity
broadcom CWE-798
critical
9.8
2022-02-14 CVE-2022-23992 Improper Input Validation vulnerability in Broadcom Xcom Data Transport 11.6
XCOM Data Transport for Windows, Linux, and UNIX 11.6 releases contain a vulnerability due to insufficient input validation that could potentially allow remote attackers to execute arbitrary commands with elevated privileges.
network
low complexity
broadcom CWE-20
critical
9.8