First published: Tue Aug 15 2023(Updated: )
Broadcom RAID Controller Web server (nginx) is serving private server-side files without any authentication on Linux
Credit: cret@cert.org cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Broadcom RAID Controller web interface | =51.12.0-2779 | |
Linux Kernel | ||
Broadcom RAID Controller web interface | =51.12.0-2779 | |
Linux Kernel |
This issue is fixed in 7.017.011.000. For more information please contact your Broadcom representative.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for Broadcom RAID Controller Web server serving private server-side files without authentication is CVE-2023-4335.
The severity level of CVE-2023-4335 is high with a severity value of 7.5.
CVE-2023-4335 does not impact Linux directly, but the Broadcom RAID Controller Web server running on Linux is affected.
No, authentication is not required to access private server-side files in Broadcom RAID Controller Web server.
You can find more information about this vulnerability on the Broadcom Product Security Center at https://www.broadcom.com/support/resources/product-security-center.