CVE-2023-4338: Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not provide X-Content-Type-Options Headers
Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not provide X-Content-Type-Options Headers
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this Broadcom RAID Controller web interface vulnerability?
The vulnerability ID for this Broadcom RAID Controller web interface vulnerability is CVE-2023-4338.
What is the severity level of CVE-2023-4338?
The severity level of CVE-2023-4338 is critical with a score of 9.8.
How does this vulnerability affect the Broadcom RAID Controller web interface?
This vulnerability affects the Broadcom RAID Controller web interface due to an insecure default configuration of HTTP that does not provide X-Content-Type-Options Headers.
What is the affected software version?
The affected software version is 51.12.0-2779 of the Broadcom RAID Controller web interface.
How can I fix this vulnerability?
To fix this vulnerability, it is recommended to update to a secure version of the Broadcom RAID Controller web interface software and configure it to use HTTPS instead of HTTP.