First published: Tue Aug 15 2023(Updated: )
Broadcom RAID Controller web interface is vulnerable to exposure of private keys used for CIM stored with insecure file permissions
Credit: cret@cert.org cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom RAID Controller web interface | =51.12.0-2779 | |
=51.12.0-2779 |
This issue is fixed in 7.017.011.000. For more information please contact your Broadcom representative.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-4339.
The title of the vulnerability is 'Broadcom RAID Controller web interface is vulnerable to exposure of private keys used for CIM stored...'
The vulnerability involves the exposure of private keys used for CIM stored with insecure file permissions on the Broadcom RAID Controller web interface.
The severity rating of the vulnerability is high with a value of 7.5.
To fix the vulnerability, update the Broadcom RAID Controller web interface to a version that addresses the insecure file permission issue.