Skip to main content

Vendor archive

broadcom CVEs

Beta · best-effort

644 CVEs tagged to vendor broadcom131 Critical, 250 High, 242 Medium, 21 Low, 0 Unrated.

CVE-2020-12595

Published Dec 10, 2020

An information disclosure flaw allows a malicious, authenticated, privileged web UI user to obtain a password for a remote SCP backup server that they might not otherwise be autho…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-12594

Published Dec 10, 2020

A privilege escalation flaw allows a malicious, authenticated, privileged CLI user to escalate their privileges on the system and gain full control over the SMG appliance. This af…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-3993

Published Oct 20, 2020

VMware NSX-T (3.x before 3.0.2, 2.5.x before 2.5.2.2.0) contains a security vulnerability that exists in the way it allows a KVM host to download and install packages from NSX man…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2020-24265

Published Oct 19, 2020

An issue was discovered in tcpreplay tcpprep v4.3.3. There is a heap buffer overflow vulnerability in MemcmpInterceptorCommon() that can make tcpprep crash and cause a denial of s…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15374

Published Sep 25, 2020

Rest API in Brocade Fabric OS v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c is vulnerable to multiple instances of reflected input.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-15373

Published Sep 25, 2020

Multiple buffer overflow vulnerabilities in REST API in Brocade Fabric OS versions v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c could allow remote unauthenticated att…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-15372

Published Sep 25, 2020

A vulnerability in the command-line interface in Brocade Fabric OS before Brocade Fabric OS v8.2.2a1, 8.2.2c, v7.4.2g, v8.2.0_CBN3, v8.2.1e, v8.1.2k, v9.0.0, could allow a local a…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15371

Published Sep 25, 2020

Brocade Fabric OS versions before Brocade Fabric OS v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, contains code injection and privilege escalation vulnerability.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-15370

Published Sep 25, 2020

Brocade Fabric OS versions before Brocade Fabric OS v7.4.2g could allow an authenticated, remote attacker to view a user password in cleartext. The vulnerability is due to incorre…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15369

Published Sep 25, 2020

Supportlink CLI in Brocade Fabric OS Versions v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c does not obfuscate the password field, which could expose users’ credential…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-16212

Published Sep 25, 2020

A vulnerability in Brocade SANnav versions before v2.1.0 could allow a remote authenticated attacker to conduct an LDAP injection. The vulnerability could allow a remote attacker…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6449

Published Sep 25, 2020

Host Header Injection vulnerability in the http management interface in Brocade Fabric OS versions before v9.0.0 could allow a remote attacker to exploit this vulnerability by inj…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-6448

Published Sep 25, 2020

A vulnerability in the management interface in Brocade Fabric OS Versions before Brocade Fabric OS v9.0.0 could allow a remote attacker to perform a denial of service attack on th…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6447

Published Sep 25, 2020

A Reflective XSS Vulnerability in HTTP Management Interface in Brocade Fabric OS versions before Brocade Fabric OS v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, v7.4.2g could al…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15778

Published Jul 24, 2020

scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reported…

CVSS 7.4 · High

CVE-2018-6446

Published Jun 29, 2020

A vulnerability in Brocade Network Advisor Version Before 14.3.1 could allow an unauthenticated, remote attacker to log in to the JBoss Administration interface of an affected sys…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-12695

Published Jun 8, 2020

The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment t…

CVSS 7.5 · High
evidence mentions
4
Buzz score
24.1
Showing 301-325 of 644 CVEsPage 13 of 26