Broadcom's vulnerability footprint spans a large and diverse portfolio of storage networking, fabric infrastructure, and backup software solutions that serve enterprise data centers and mission-critical environments, representing a substantial and widely deployed attack surface. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a frequent tendency toward public exploit code availability, creating material risk for exposed deployments. The exposure recurs across flagship products including Fabric Operating System, SAN management software, and BackupEdge components, with recurring weaknesses centered on input validation, memory-safety issues, and web-application flaws such as cross-site scripting that are characteristic of complex enterprise infrastructure. Defenders should prioritize patching for fabric switches and backup appliances exposed to untrusted networks, as these products occupy high-value positions in backup and replication workflows. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Broadcom over time
Signals from CVEs in this vendor scope (653 CVEs).
653 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-0160HIGH The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive inform | Apr 7, 2014 | 7.5 | 99 | YES | YES |
CVE-2021-40438CRITICAL A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. | Sep 16, 2021 | 9.0 | 97 | YES | YES |
CVE-2018-1273CRITICAL Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of s | Apr 11, 2018 | 9.8 | 97 | YES | YES |
CVE-2010-0425HIGH modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure | Mar 5, 2010 | 10.0 | 91 | NO | YES |
CVE-2011-1653HIGH Multiple SQL injection vulnerabilities in the Unified Network Control (UNC) Server in CA Total Defense (TD) r12 before SE2 allow remote attackers to execute arbitrary SQL commands | Apr 18, 2011 | 10.0 | 90 | NO | YES |
CVE-2020-8012CRITICAL CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a buffer overflow vulnerability in the robot (controller) component. A remote attacker | Feb 18, 2020 | 9.8 | 86 | NO | YES |
CVE-2008-4397HIGH Directory traversal vulnerability in the RPC interface (asdbapi.dll) in CA ARCserve Backup (formerly BrightStor ARCserve Backup) r11.1 through r12.0 allows remote attackers to exec | Oct 14, 2008 | 10.0 | 84 | NO | YES |
CVE-2005-2668HIGH Multiple buffer overflows in Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allow remote attackers to execute arb | Aug 23, 2005 | 10.0 | 84 | NO | YES |
CVE-2007-2139HIGH Multiple stack-based buffer overflows in the SUN RPC service in CA (formerly Computer Associates) BrightStor ARCserve Media Server, as used in BrightStor ARCserve Backup 9.01 throu | Apr 25, 2007 | 10.0 | 83 | NO | YES |
CVE-2007-0449HIGH Multiple buffer overflows in LGSERVER.EXE in CA BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.1 SP1, Mobile Backup r4.0, Desktop and Business Protection Sui | Jan 23, 2007 | 10.0 | 83 | NO | YES |
Signals from CVEs in this vendor scope (653 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Broadcom.
Media articles that mention a CVE ID that affects a product developed by Broadcom — matched by CVE ID, not by vendor name.