VYPR

Vendor CVEs

Broadcom Corporation

All CVEs

798 total · sorted by risk
  • CVE-2024-29950HigApr 17, 2024
    risk 0.49cvss 7.5epss 0.00

    The class FileTransfer implemented in Brocade SANnav before v2.3.1, v2.3.0a, uses the ssh-rsa signature scheme, which has a SHA-1 hash. The vulnerability could allow a remote, unauthenticated attacker to perform a man-in-the-middle attack.

  • CVE-2023-4343HigAug 15, 2023
    risk 0.49cvss 7.5epss 0.00

    Broadcom RAID Controller web interface is vulnerable due to exposure of sensitive password information in the URL as a URL search parameter

  • CVE-2023-4339HigAug 15, 2023
    risk 0.49cvss 7.5epss 0.01

    Broadcom RAID Controller web interface is vulnerable to exposure of private keys used for CIM stored with insecure file permissions

  • CVE-2023-4335HigAug 15, 2023
    risk 0.49cvss 7.5epss 0.00

    Broadcom RAID Controller Web server (nginx) is serving private server-side files without any authentication on Linux

  • CVE-2023-4334HigAug 15, 2023
    risk 0.49cvss 7.5epss 0.01

    Broadcom RAID Controller Web server (nginx) is serving private files without any authentication

  • CVE-2023-4332HigAug 15, 2023
    risk 0.49cvss 7.5epss 0.01

    Broadcom RAID Controller web interface is vulnerable due to Improper permissions on the log file

  • CVE-2023-4331HigAug 15, 2023
    risk 0.49cvss 7.5epss 0.00

    Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that support obsolete and vulnerable TLS protocols

  • CVE-2023-4326HigAug 15, 2023
    risk 0.49cvss 7.5epss 0.00

    Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that supports obsolete SHA1-based ciphersuites

  • CVE-2023-27788HigMar 16, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue found in TCPrewrite v.4.4.3 allows a remote attacker to cause a denial of service via the ports2PORT function at the portmap.c:69 endpoint.

  • CVE-2023-27787HigMar 16, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the parse_list function at the list.c:81 endpoint.

  • CVE-2023-27785HigMar 16, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue found in TCPreplay TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the parse endpoints function.

  • CVE-2023-27784HigMar 16, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue found in TCPReplay v.4.4.3 allows a remote attacker to cause a denial of service via the read_hexstring function at the utils.c:309 endpoint.

  • CVE-2022-37017HigDec 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Symantec Endpoint Protection (Windows) agent, prior to 14.3 RU6/14.3 RU5 Patch 1, may be susceptible to a Security Control Bypass vulnerability, which is a type of issue that can potentially allow a threat actor to circumvent existing security controls. This CVE applies narrowly…

  • CVE-2022-28168HigJun 27, 2022
    risk 0.49cvss 7.5epss 0.01

    In Brocade SANnav before Brocade SANnav v2.2.0.2 and Brocade SANnav2.1.1.8, encoded scp-server passwords are stored using Base64 encoding, which could allow an attacker able to access log files to easily decode the passwords.

  • CVE-2022-28166HigJun 27, 2022
    risk 0.49cvss 7.5epss 0.01

    In Brocade SANnav version before SANN2.2.0.2 and Brocade SANNav before 2.1.1.8, the implementation of TLS/SSL Server Supports the Use of Static Key Ciphers (ssl-static-key-ciphers) on ports 443 & 18082.

  • CVE-2022-33756HigJun 16, 2022
    risk 0.49cvss 7.5epss 0.01

    CA Automic Automation 12.2 and 12.3 contain an entropy weakness vulnerability in the Automic AutomationEngine that could allow a remote attacker to potentially access sensitive data.

  • CVE-2022-33751HigJun 16, 2022
    risk 0.49cvss 7.5epss 0.01

    CA Automic Automation 12.2 and 12.3 contain an insecure memory handling vulnerability in the Automic agent that could allow a remote attacker to potentially access sensitive data.

  • CVE-2022-33739HigJun 16, 2022
    risk 0.49cvss 7.5epss 0.01

    CA Clarity 15.8 and below and 15.9.0 contain an insecure XML parsing vulnerability that could allow a remote attacker to potentially view the contents of any file on the system.

  • CVE-2021-42773HigNov 12, 2021
    risk 0.49cvss 7.5epss 0.01

    Broadcom Emulex HBA Manager/One Command Manager versions before 11.4.425.0 and 12.8.542.31, if not installed in Strictly Local Management mode, could allow a user to retrieve an arbitrary file from a remote host with the GetDumpFile command. In non-secure mode, the user is…

  • CVE-2020-15380HigJun 9, 2021
    risk 0.49cvss 7.5epss 0.01

    Brocade SANnav before version 2.1.1 logs account credentials at the ‘trace’ logging level.

  • CVE-2020-15379HigJun 9, 2021
    risk 0.49cvss 7.5epss 0.01

    Brocade SANnav before v.2.1.0a could allow remote attackers cause a denial-of-service condition due to a lack of proper validation, of the length of user-supplied data as name for custom field name.

  • CVE-2020-15383HigJun 9, 2021
    risk 0.49cvss 7.5epss 0.01

    Running security scans against the SAN switch can cause config and secnotify processes within the firmware before Brocade Fabric OS v9.0.0, v8.2.2d and v8.2.1e to consume all memory leading to denial of service impacts possibly including a switch panic.

  • CVE-2020-15381HigJun 9, 2021
    risk 0.49cvss 7.5epss 0.01

    Brocade SANnav before version 2.1.1 contains an Improper Authentication vulnerability that allows cleartext transmission of authentication credentials of the jmx server.

  • CVE-2021-28248HigMar 26, 2021
    risk 0.49cvss 7.5epss 0.01

    CA eHealth Performance Manager through 6.3.2.12 is affected by Improper Restriction of Excessive Authentication Attempts. An attacker is able to perform an arbitrary number of /web/frames/ authentication attempts using different passwords, and eventually gain access to a…

  • CVE-2021-27219HigFeb 15, 2021
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in GNOME GLib before 2.66.6 and 2.67.x before 2.67.3. The function g_bytes_new has an integer overflow on 64-bit platforms due to an implicit cast from 64 bits to 32 bits. The overflow could potentially lead to memory corruption.

  • CVE-2021-27218HigFeb 15, 2021
    risk 0.49cvss 7.5epss 0.04

    An issue was discovered in GNOME GLib before 2.66.7 and 2.67.x before 2.67.4. If g_byte_array_new_take() was called with a buffer of 4GB or more on a 64-bit platform, the length would be truncated modulo 2**32, causing unintended length truncation.

  • CVE-2020-29478HigJan 5, 2021
    risk 0.49cvss 7.5epss 0.01

    CA Service Catalog 17.2 and 17.3 contain a vulnerability in the default configuration of the Setup Utility that may allow a remote attacker to cause a denial of service condition.

  • CVE-2020-12593HigNov 18, 2020
    risk 0.49cvss 7.5epss 0.02

    Symantec Endpoint Detection & Response, prior to 4.5, may be susceptible to an information disclosure issue, which is a type of vulnerability that could potentially allow unauthorized access to data.

  • CVE-2020-24266HigOct 19, 2020
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in tcpreplay tcpprep v4.3.3. There is a heap buffer overflow vulnerability in get_l2len() that can make tcpprep crash and cause a denial of service.

  • CVE-2020-24265HigOct 19, 2020
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in tcpreplay tcpprep v4.3.3. There is a heap buffer overflow vulnerability in MemcmpInterceptorCommon() that can make tcpprep crash and cause a denial of service.

  • CVE-2018-6448HigSep 25, 2020
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the management interface in Brocade Fabric OS Versions before Brocade Fabric OS v9.0.0 could allow a remote attacker to perform a denial of service attack on the vulnerable host.

  • CVE-2020-15778HigJul 24, 2020
    risk 0.49cvss 7.4epss 0.13

    scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that…

  • CVE-2020-5839HigJul 8, 2020
    risk 0.49cvss 7.5epss 0.02

    Symantec Endpoint Detection And Response, prior to 4.4, may be susceptible to an information disclosure issue, which is a type of vulnerability that could potentially allow unauthorized access to data.

  • CVE-2020-12243HigApr 28, 2020
    risk 0.49cvss 7.5epss 0.04

    In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon crash).

  • CVE-2020-11662HigApr 15, 2020
    risk 0.49cvss 7.5epss 0.03

    CA API Developer Portal 4.3.1 and earlier handles requests insecurely, which allows remote attackers to exploit a Cross-Origin Resource Sharing flaw and access sensitive information.

  • CVE-2020-8011HigFeb 18, 2020
    risk 0.49cvss 7.5epss 0.02

    CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a null pointer dereference vulnerability in the robot (controller) component. A remote attacker can crash the Controller service.

  • CVE-2019-16204HigFeb 5, 2020
    risk 0.49cvss 7.5epss 0.01

    Brocade Fabric OS Versions before v7.4.2f, v8.2.2a, v8.1.2j and v8.2.1d could expose external passwords, common secrets or authentication keys used between the switch and an external server.

  • CVE-2019-16203HigFeb 5, 2020
    risk 0.49cvss 7.5epss 0.01

    Brocade Fabric OS Versions before v8.2.2a and v8.2.1d could expose the credentials of the remote ESRS server when these credentials are given as a command line option when configuring the ESRS client.

  • CVE-2019-11287HigNov 23, 2019
    risk 0.49cvss 7.5epss 0.05

    Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is vulnerable to a denial of service attack. The "X-Reason"…

  • CVE-2019-16208HigNov 8, 2019
    risk 0.49cvss 7.5epss 0.00

    Password-based encryption (PBE) algorithm, of Brocade SANnav versions before v2.0, has a weakness in generating cryptographic keys that may allow an attacker to decrypt passwords used with several services (Radius, TACAS, etc.).

  • CVE-2018-6445HigJan 22, 2019
    risk 0.49cvss 7.5epss 0.02

    A Vulnerability in Brocade Network Advisor versions before 14.0.3 could allow a remote unauthenticated attacker to export the current user database which includes the encrypted (not hashed) password of the systems. The attacker could gain access to the Brocade Network Advisor…

  • CVE-2018-19634HigJan 22, 2019
    risk 0.49cvss 7.5epss 0.01

    CA Service Desk Manager 14.1 and 17 contain a vulnerability that can allow a malicious actor to access survey information.

  • CVE-2018-6434HigNov 8, 2018
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the web management interface of Brocade Fabric OS versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow attackers to intercept or manipulate a user's session ID.

  • CVE-2018-13823HigAug 30, 2018
    risk 0.49cvss 7.5epss 0.02

    An XML external entity vulnerability in the XOG functionality, in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows remote attackers to access sensitive information.

  • CVE-2018-13822HigAug 30, 2018
    risk 0.49cvss 7.5epss 0.01

    Unprotected storage of credentials in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows attackers to access sensitive information.

  • CVE-2018-13112HigJul 3, 2018
    risk 0.49cvss 7.5epss 0.02

    get_l2len in common/get.c in Tcpreplay 4.3.0 beta1 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via crafted packets, as demonstrated by tcpprep.

  • CVE-2018-9028HigJun 18, 2018
    risk 0.49cvss 7.5epss 0.01

    Weak cryptography used for passwords in CA Privileged Access Manager 2.x reduces the complexity for password cracking.

  • CVE-2018-9026HigJun 18, 2018
    risk 0.49cvss 7.5epss 0.01

    A session fixation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to hijack user sessions with a specially crafted request.

  • CVE-2018-9025HigJun 18, 2018
    risk 0.49cvss 7.5epss 0.01

    An input validation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to poison log files with specially crafted input.

  • CVE-2018-1259HigMay 11, 2018
    risk 0.49cvss 7.5epss 0.05

    Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying library XMLBeam does…

Page 6 of 16