CVE-2023-4327: Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Linux
Published Aug 15, 2023
·Updated
Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Linux
Affected Software
4 affected components
All of the following
Broadcom RAID Controller web interface=51.12.0-2779
Linux Linux kernel
Broadcom RAID Controller web interface=51.12.0-2779
Linux Linux kernel
Remediation
Information
This issue is fixed in 7.017.011.000. For more information please contact your Broadcom representative.
Event History
Aug 15, 2023
CVE Published
via MITRE·06:25 PM
Data Sourced
via MITRE·06:25 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this Broadcom RAID Controller web interface vulnerability?
The vulnerability ID for this Broadcom RAID Controller web interface vulnerability is CVE-2023-4327.
2
What is the severity rating of CVE-2023-4327?
The severity rating of CVE-2023-4327 is medium (5.5).
3
What is the affected software in CVE-2023-4327?
The affected software in CVE-2023-4327 is the Broadcom RAID Controller web interface version 51.12.0-2779 on Linux.
4
What is the impact of CVE-2023-4327?
CVE-2023-4327 allows any local user on Linux to access sensitive data and encryption keys used in the Broadcom RAID Controller web interface.
5
Is there any official reference for CVE-2023-4327?
Yes, there is an official reference for CVE-2023-4327. You can find it at https://www.broadcom.com/support/resources/product-security-center.