First published: Tue Aug 15 2023(Updated: )
Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not provide X-Content-Type-Options Headers
Credit: cret@cert.org cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom RAID Controller web interface | =51.12.0-2779 |
This issue is fixed in 7.017.011.000. For more information please contact your Broadcom representative.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Broadcom RAID Controller web interface vulnerability is CVE-2023-4338.
The severity level of CVE-2023-4338 is critical with a score of 9.8.
This vulnerability affects the Broadcom RAID Controller web interface due to an insecure default configuration of HTTP that does not provide X-Content-Type-Options Headers.
The affected software version is 51.12.0-2779 of the Broadcom RAID Controller web interface.
To fix this vulnerability, it is recommended to update to a secure version of the Broadcom RAID Controller web interface software and configure it to use HTTPS instead of HTTP.