Description
Broadcom RAID Controller web interface doesn’t enforce SSL cipher ordering by server
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6Attack Vector: Local
Complexity: Low
Privileges: Low
User Interaction: None
Scope: Unchanged
Confidentiality: High
Integrity: None
Availability: None
Affected Packages2 packages
🔴Vulnerability Details
2CVEListBroadcom RAID Controller web interface doesn’t enforce SSL cipher ordering by server↗2023-08-15 ▶ GHSAGHSA-m89f-h769-x259: Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user o↗2023-08-15 ▶