CA Technologies - A Broadcom Company

First CVE: Sep 22, 2017Active for: 9 years
91
CVEs Published
More CVEs Published than 69% of tracked CNAs
11.4
Avg CVEs / Year
More Avg CVEs / Year than 57% of tracked CNAs
7.9
Avg CVSS Score
Higher Avg CVSS Score than 85% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by CA Technologies - A Broadcom Company as a CNA, 22.0% affect products that CA Technologies - A Broadcom Company develops as a vendor.

22.0%
78.0%
Self-reported: 20Third-party: 71

Of all the CVEs published that affect products developed by CA Technologies - A Broadcom Company, 14.5% are self-published by CA Technologies - A Broadcom Company as a CNA.

14.5%
85.5%
Self-published: 20Published by other CNAs: 118

Trends Over Time

The number and severity of CVEs published by CA Technologies - A Broadcom Company over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 22, 2017
8 years ago
Most Recent CVE
May 19, 2026
66 days ago

Top CVEs

All CVEs published by CA Technologies - A Broadcom Company as a CNA, regardless of affected vendor or product.

91 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a buffer overflow vulnerability in the robot (controller) component. A remote attacker
Feb 18, 20209.886NOYES
CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains an improper ACL handling vulnerability in the robot (controller) component. A remote at
Feb 18, 20209.870NOYES
An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary code or commands by poisoning a configuration
Jun 18, 20189.853NOYES
An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary commands with specially crafted requests.
Jun 18, 20189.852NOYES
Insecure deserialization of a specially crafted serialized object, in CA Release Automation 6.5 and earlier, allows attackers to potentially execute arbitrary code.
Aug 30, 20189.851NOYES
An improper input validation vulnerability in CA Privileged Access Manager 2.4.4.4 and earlier allows remote attackers to execute arbitrary commands.
Jun 18, 20189.845NOYES
Execution with unnecessary privileges vulnerability in Broadcom Automic Automation Agent Unix on Linux x64, Linux Power 64 BE, Linux Power 64 LE, zLinux (zSeries), AIX, Solaris x64
May 19, 20268.534NONO
Broadcom Automic Automation Agent Unix versions < 24.3.0 HF4 and < 21.0.13 HF1 allow low privileged users who have execution rights on the agent executable to escalate their privil
May 20, 20258.533NOYES
An access vulnerability in CA Common Services DIA of CA Technologies Client Automation 14 and Workload Automation AE 11.3.5, 11.3.6 allows a remote attacker to execute arbitrary co
Sep 6, 20199.832NONO
CA Workload Control Center before r11.4 SP6 allows remote attackers to execute arbitrary code via a crafted HTTP request.
Apr 11, 20189.832NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA91 CVEs
Severity distribution among all CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local6 (6.6%)
Network83 (91.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (2.2%)
Attack Complexity
Low87 (95.6%)
High4 (4.4%)
Unknown0 (0.0%)
User Interaction
None77 (84.6%)
Unknown0 (0.0%)
Required14 (15.4%)
Privileges Required
Low23 (25.3%)
High2 (2.2%)
None66 (72.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (91 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
2.2% of CVEs· 92nd percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
6 CVEs
6.6% of CVEs· 97th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by CA Technologies - A Broadcom Company as a CNA.

Media Mentions

Media articles that mention a CVE ID published by CA Technologies - A Broadcom Company as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs