Raid Controller Web Interface
Vendor:
First CVE: Aug 15, 2023 · Active for 2 years
22
Total CVEs
More Total CVEs than 94% of tracked products
22.0
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
8.3
Avg CVSS
Higher Avg CVSS than 74% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Raid Controller Web Interface over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 15, 2023
2 years ago
Most Recent CVE
Aug 15, 2023
1,074 days ago
CVE Severity & Scoring
Raid Controller Web Interface22 CVEs
18%
32%
50%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (13.6%)
Network19 (86.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None22 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low4 (18.2%)
High0 (0.0%)
None18 (81.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-4338CRITICAL Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not provide X-Content-Type-Options Headers | Aug 15, 2023 | 9.8 | 31 | NO | NO |
CVE-2023-4324CRITICAL Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP Content-Security-Policy headers | Aug 15, 2023 | 9.8 | 31 | NO | NO |
CVE-2023-4342CRITICAL Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP strict-transport-security policy | Aug 15, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-4336CRITICAL Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard cookies with Secure attribute | Aug 15, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-4344CRITICAL Broadcom RAID Controller web interface is vulnerable to insufficient randomness due to improper use of ssl.rnd to setup CIM connection | Aug 15, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-4325CRITICAL Broadcom RAID Controller web interface is vulnerable due to usage of Libcurl with LSA has known vulnerabilities | Aug 15, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-4323CRITICAL Broadcom RAID Controller web interface is vulnerable to improper session management of active sessions on Gateway setup | Aug 15, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-4341CRITICAL Broadcom RAID Controller is vulnerable to Privilege escalation to root due to creation of insecure folders by Web GUI | Aug 15, 2023 | 9.8 | 27 | NO | NO |
CVE-2023-4340CRITICAL Broadcom RAID Controller is vulnerable to Privilege escalation by taking advantage of the Session prints in the log file | Aug 15, 2023 | 9.8 | 24 | NO | NO |
CVE-2023-4337CRITICAL Broadcom RAID Controller web interface is vulnerable to improper session handling of managed servers on Gateway installation | Aug 15, 2023 | 9.8 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (22 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (22 CVEs).
Media Mentions
Signals from CVEs in this product scope (22 CVEs).
Top CNAs Publishing CVEs For Raid Controller Web Interface
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 51.12.0-2779 | 22 | 8.3 | 0.5% | 0 | 0 |