CVE-2023-4345Sensitive Information Exposure in LSI Storage Authority

Severity
6.5MEDIUMNVD
EPSS
0.0%
top 89.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 15

Description

Broadcom RAID Controller web interface is vulnerable client-side control bypass leads to unauthorized data access for low privileged user

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

CVEListV5intel/raid_web_console_3< 7.017.011.000
CVEListV5broadcom/lsi_storage_authority< 7.017.011.000

🔴Vulnerability Details

2
GHSA
GHSA-wfv7-gj87-q7qv: Broadcom RAID Controller web interface is vulnerable client-side control bypass leads to unauthorized data access for low privileged user2023-08-15
CVEList
Broadcom RAID Controller web interface is vulnerable client-side control bypass2023-08-15
CVE-2023-4345 — Sensitive Information Exposure | cvebase