CVE-2023-4328Insufficiently Protected Credentials in LSI Storage Authority

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 92.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 15

Description

Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Windows

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Linux2023-08-15
GHSA
GHSA-c2mc-q4gg-xgm7: Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user o2023-08-15
CVE-2023-4328 — Insufficiently Protected Credentials | cvebase