Broadcom RAID Controller web interface is vulnerable to insufficient randomness due to improper use of ssl.rnd to setup CIM connection
CVE-2023-4344
9.8CRITICAL
Key Information:
- Vendor
Broadcom
- Vendor
- CVE Published:
- 15 August 2023
What is CVE-2023-4344?
The web interface of the Broadcom RAID Controller is susceptible to insufficient randomness due to improper implementation of the ssl.rnd function during the establishment of CIM connections. This shortfall can lead to potential security risks, enabling attackers to exploit the weakness and undermine the security of data transactions.
Affected Version(s)
LSI Storage Authority (LSA) 0
RAID Web Console 3 (RWC3) 0 < 7.017.011.000