CVE-2023-4335: Broadcom RAID Controller Web server (nginx) is serving private server-side files without any authentication on Linux
Published Aug 15, 2023
·Updated
Broadcom RAID Controller Web server (nginx) is serving private server-side files without any authentication on Linux
Affected Software
4 affected components
All of the following
Broadcom RAID Controller web interface=51.12.0-2779
Linux Linux kernel
Broadcom RAID Controller web interface=51.12.0-2779
Linux Linux kernel
Remediation
Information
This issue is fixed in 7.017.011.000. For more information please contact your Broadcom representative.
Event History
Aug 15, 2023
CVE Published
via MITRE·06:25 PM
Data Sourced
via MITRE·06:25 PM
RemedyDescription
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for Broadcom RAID Controller Web server serving private server-side files without authentication?
The vulnerability ID for Broadcom RAID Controller Web server serving private server-side files without authentication is CVE-2023-4335.
2
What is the severity level of CVE-2023-4335?
The severity level of CVE-2023-4335 is high with a severity value of 7.5.
3
How does CVE-2023-4335 impact Linux?
CVE-2023-4335 does not impact Linux directly, but the Broadcom RAID Controller Web server running on Linux is affected.
4
Is authentication required to access private server-side files in Broadcom RAID Controller Web server?
No, authentication is not required to access private server-side files in Broadcom RAID Controller Web server.
5
Where can I find more information about this vulnerability?
You can find more information about this vulnerability on the Broadcom Product Security Center at https://www.broadcom.com/support/resources/product-security-center.