Broadcom RAID Controller web interface is vulnerable to improper session management of active sessions on Gateway setup
CVE-2023-4323
9.8CRITICAL
Key Information:
- Vendor
- Broadcom
- Vendor
- CVE Published:
- 15 August 2023
Summary
The Broadcom RAID Controller web interface is susceptible to vulnerabilities arising from improper management of active sessions during Gateway setup. This oversight can allow unauthorized access to sensitive data and functionalities, potentially compromising the security of the system. Organizations using affected versions should evaluate their configurations and consider immediate measures to mitigate risks associated with this vulnerability, thereby safeguarding their data integrity and system operations.
Affected Version(s)
LSI Storage Authority (LSA) 0
RAID Web Console 3 (RWC3) 0 < 7.017.011.000
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Intel DCG