Raid Controller Web Interface

Vendor:

First CVE: Aug 15, 2023 · Active for 2 years

22
Total CVEs
More Total CVEs than 94% of tracked products
22.0
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
8.3
Avg CVSS
Higher Avg CVSS than 74% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Raid Controller Web Interface over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 15, 2023
2 years ago
Most Recent CVE
Aug 15, 2023
1,074 days ago

CVE Severity & Scoring

Raid Controller Web Interface22 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local3 (13.6%)
Network19 (86.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None22 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low4 (18.2%)
High0 (0.0%)
None18 (81.8%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not provide X-Content-Type-Options Headers
Aug 15, 20239.831NONO
Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP Content-Security-Policy headers
Aug 15, 20239.831NONO
Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP strict-transport-security policy
Aug 15, 20239.830NONO
Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard cookies with Secure attribute
Aug 15, 20239.830NONO
Broadcom RAID Controller web interface is vulnerable to insufficient randomness due to improper use of ssl.rnd to setup CIM connection
Aug 15, 20239.829NONO
Broadcom RAID Controller web interface is vulnerable due to usage of Libcurl with LSA has known vulnerabilities
Aug 15, 20239.829NONO
Broadcom RAID Controller web interface is vulnerable to improper session management of active sessions on Gateway setup
Aug 15, 20239.829NONO
Broadcom RAID Controller is vulnerable to Privilege escalation to root due to creation of insecure folders by Web GUI
Aug 15, 20239.827NONO
Broadcom RAID Controller is vulnerable to Privilege escalation by taking advantage of the Session prints in the log file
Aug 15, 20239.824NONO
Broadcom RAID Controller web interface is vulnerable to improper session handling of managed servers on Gateway installation
Aug 15, 20239.824NONO

Exploit Exposure

Signals from CVEs in this product scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (22 CVEs).

Media Mentions

Signals from CVEs in this product scope (22 CVEs).

Top CNAs Publishing CVEs For Raid Controller Web Interface

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
51.12.0-2779228.30.5%00