First published: Tue Aug 15 2023(Updated: )
Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Linux
Credit: cret@cert.org cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom RAID Controller web interface | =51.12.0-2779 | |
Linux Linux kernel | ||
All of | ||
=51.12.0-2779 | ||
This issue is fixed in 7.017.011.000. For more information please contact your Broadcom representative.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Broadcom RAID Controller web interface vulnerability is CVE-2023-4327.
The severity rating of CVE-2023-4327 is medium (5.5).
The affected software in CVE-2023-4327 is the Broadcom RAID Controller web interface version 51.12.0-2779 on Linux.
CVE-2023-4327 allows any local user on Linux to access sensitive data and encryption keys used in the Broadcom RAID Controller web interface.
Yes, there is an official reference for CVE-2023-4327. You can find it at https://www.broadcom.com/support/resources/product-security-center.