Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that supports obsolete SHA1-based ciphersuites
CVE-2023-4326
7.5HIGH
Key Information:
- Vendor
Broadcom
- Vendor
- CVE Published:
- 15 August 2023
What is CVE-2023-4326?
The Broadcom RAID Controller web interface is susceptible to vulnerabilities due to an insecure default TLS configuration. This configuration permits the use of outdated SHA1-based ciphersuites, which can expose communications to potential interception and exploitation. Organizations using this product should take immediate action to enhance their TLS settings, ensuring the use of modern, secure ciphers in order to protect their data and maintain integrity across their network communications. Further information is available on Broadcom's support page.
Affected Version(s)
LSI Storage Authority (LSA) 0
RAID Web Console 3 (RWC3) 0