Broadcom CVE Vulnerabilities & CVE List (646)

Products (CPE): — CVEs: 646

Broadcom vulnerability overview

Aggregates CVE and security vulnerability intelligence across all Broadcom-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk input validation, vendor risk sql injection, and vendor risk open redirect and related problems; some flaws may lead to vendor impact file overwrite and vendor impact data exposure.

Vulnerability distribution trend (last 24 months)

Showing 101120 of 646 CVEs
«« First « Prev Page 6 / 33 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2024-29965 In Brocade SANnav before v2.3.1, and v2.3.0a, it is possible to back up the appliance from the web interface or the command line interface ("SSH"). The resulting backups are world-readable. A local attacker can recover backup files, restore them to a new malicious appliance, and retrieve the passwords of all the switches. [email protected] 6.8 0.41% 2024-04-19 2026-06-17
CVE-2024-29964 Brocade SANnav versions before v2.3.0a do not correctly set permissions on files, including docker files. An unprivileged attacker who gains access to the server can read sensitive information from these files. [email protected] 5.7 0.52% 2024-04-19 2026-06-17
CVE-2024-29962 Brocade SANnav OVA before v2.3.1 and v2.3.0a have an insecure file permission setting that makes files world-readable. This could allow a local user without the required privileges to access sensitive information or a Java binary. [email protected] 5.5 0.18% 2024-04-19 2026-06-17
CVE-2024-29963 Brocade SANnav OVA before v2.3.1, and v2.3.0a, contain hardcoded TLS keys used by Docker. Note: Brocade SANnav doesn't have access to remote Docker registries. [email protected] 1.9 0.16% 2024-04-19 2026-06-17
CVE-2024-29961 A vulnerability affects Brocade SANnav before v2.3.1 and v2.3.0a. It allows a Brocade SANnav service to send ping commands in the background at regular intervals to gridgain.com to check if updates are available for the Component. This could make an unauthenticated, remote attacker aware of the behavior and launch a supply-chain attack against a Brocade SANnav appliance. [email protected] 8.2 0.76% 2024-04-19 2026-06-17
CVE-2024-29960 In Brocade SANnav server before v2.3.1 and v2.3.0a, the SSH keys inside the OVA image are identical in the VM every time SANnav is installed. Any Brocade SAnnav VM based on the official OVA images is vulnerable to MITM over SSH. An attacker can decrypt and compromise the SSH traffic to the SANnav. [email protected] 6.8 0.31% 2024-04-19 2026-06-17
CVE-2024-29959 A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints Brocade Fabric OS switch encrypted passwords in the Brocade SANnav Standby node's support save. [email protected] 8.6 0.48% 2024-04-19 2026-06-17
CVE-2024-29958 A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints the encryption key in the console when a privileged user executes the script to replace the Brocade SANnav Management Portal standby node. This could provide attackers an additional, less protected path to acquiring the encryption key. [email protected] 7.5 0.29% 2024-04-19 2026-06-17
CVE-2024-29957 When Brocade SANnav before v2.3.1 and v2.3.0a servers are configured in Disaster Recovery mode, the encryption key is stored in the DR log files. This could provide attackers with an additional, less-protected path to acquiring the encryption key. [email protected] 7.5 0.29% 2024-04-19 2026-06-17
CVE-2024-29956 A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints the Brocade SANnav password in clear text in supportsave logs when a user schedules a switch Supportsave from Brocade SANnav. [email protected] 6.5 0.28% 2024-04-17 2026-06-17
CVE-2024-29955 A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow a privileged user to print the SANnav encrypted key in PostgreSQL startup logs. This could provide attackers with an additional, less-protected path to acquiring the encryption key. [email protected] 5.0 0.11% 2024-04-17 2026-06-17
CVE-2024-29952 A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow an authenticated user to print the Auth, Priv, and SSL key store passwords in unencrypted logs by manipulating command variables. [email protected] 5.5 0.06% 2024-04-17 2026-06-17
CVE-2024-29951 Brocade SANnav before v2.3.1 and v2.3.0a uses the SHA-1 hash in internal SSH ports that are not open to remote connection. [email protected] 5.7 0.16% 2024-04-17 2026-06-17
CVE-2024-29950 The class FileTransfer implemented in Brocade SANnav before v2.3.1, v2.3.0a, uses the ssh-rsa signature scheme, which has a SHA-1 hash. The vulnerability could allow a remote, unauthenticated attacker to perform a man-in-the-middle attack. [email protected] 7.5 0.31% 2024-04-17 2026-06-17
CVE-2023-5973 Brocade Web Interface in Brocade Fabric OS v9.x and before v9.2.0 does not properly represent the portName to the user if the portName contains reserved characters. This could allow an authenticated user to alter the UI of the Brocade Switch and change ports display. [email protected] 4.3 0.19% 2024-04-04 2026-06-17
CVE-2024-24795 HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack. Users are recommended to upgrade to version 2.4.59, which fixes this issue. [email protected] 6.3 2.87% 2024-04-04 2026-06-17
CVE-2023-38709 Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through 2.4.58. [email protected] 7.3 3.91% 2024-04-04 2026-06-17
CVE-2023-3454 Remote code execution (RCE) vulnerability in Brocade Fabric OS after v9.0 and before v9.2.0 could allow an attacker to execute arbitrary code and use this to gain root access to the Brocade switch. [email protected] 8.6 1.21% 2024-04-04 2026-06-17
CVE-2024-3024 A vulnerability was found in appneta tcpreplay up to 4.4.4. It has been classified as problematic. This affects the function get_layer4_v6 of the file /tcpreplay/src/common/get.c. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The identifier VDB-258333 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. [email protected] 5.3 0.44% 2024-03-27 2026-06-17
CVE-2023-43279 Null Pointer Dereference in mask_cidr6 component at cidr.c in Tcpreplay 4.4.4 allows attackers to crash the application via crafted tcprewrite command. [email protected] 6.5 0.67% 2024-03-12 2026-06-17
«« First « Prev Page 6 / 33 Next »
cvelogic Threat Intelligence