CVE-2023-4334: Broadcom RAID Controller Web server (nginx) is serving private files without any authentication
Published Aug 15, 2023
·Updated
Broadcom RAID Controller Web server (nginx) is serving private files without any authentication
Affected Software
1 affected component
Broadcom RAID Controller web interface=51.12.0-2779
Remediation
Information
This issue is fixed in 7.017.011.000. For more information please contact your Broadcom representative.
Event History
Aug 15, 2023
CVE Published
via MITRE·06:25 PM
Data Sourced
via MITRE·06:25 PM
RemedyDescription
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-4334.
2
What is the title of the vulnerability?
The title of the vulnerability is 'Broadcom RAID Controller Web server (nginx) is serving private files without any authentication.'
3
What is affected by this vulnerability?
The Broadcom RAID Controller web interface version 51.12.0-2779 is affected by this vulnerability.
4
What is the severity of CVE-2023-4334?
The severity of CVE-2023-4334 is high with a score of 7.5.
5
How can I fix CVE-2023-4334?
To fix CVE-2023-4334, it is recommended to apply the latest security patches or updates provided by Broadcom.