Broadcom
broadcom
645 CVEs • 275 products
Products (275)
Click to collapseToggle
Products (275)
Click to collapse
CVEs (645)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
RabbitMQ is a messaging and streaming broker. In versions 3.13.7 and prior, RabbitMQ is logging authorization headers in plaintext encoded in base64. When querying RabbitMQ api with HTTP/s with basic authentication it cr...Show more |
1Broadcom 1Fabric Operating System Jun 17, 2026 Jun 19, 2025 4.8 MEDIUM· v4 2.3 LOW· v3 N/A· v2 A path transversal vulnerability in Brocade Fabric OS 9.1.0 through 9.2.2 could allow a local admin user to gain access to files outside the intended directory potentially leading to the disclosure of sensitive inform...Show more |
2Broadcom Vmware4Cloud Foundation Telco Cloud InfrastructureTelco Cloud Platform+1 moreJun 17, 2026 Jun 4, 2025 N/A· v4 5.9 MEDIUM· v3 N/A· v2 VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the router port due to improper input validation. |
2Broadcom Vmware4Cloud Foundation Telco Cloud InfrastructureTelco Cloud Platform+1 moreJun 17, 2026 Jun 4, 2025 N/A· v4 6.9 MEDIUM· v3 N/A· v2 VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the gateway firewall due to improper input validation. |
2Broadcom Vmware4Cloud Foundation Telco Cloud InfrastructureTelco Cloud Platform+1 moreJun 17, 2026 Jun 4, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 VMware NSX Manager UI is vulnerable to a stored Cross-Site Scripting (XSS) attack due to improper input validation. |
tcpreplay v4.4.4 was discovered to contain an infinite loop via the tcprewrite function at get.c. |
1Broadcom 2Bitnami Bitnami/pgpoolJun 17, 2026 May 13, 2025 9.4 CRITICAL· v4 7.5 HIGH· v3 N/A· v2 The bitnami/pgpool Docker image, and the bitnami/postgres-ha k8s chart, under default configurations, comes with an 'repmgr' user that allows unauthenticated access to the database inside the cluster. The PGPOOL_SR_CHECK...Show more |
Symantec Endpoint Protection Windows Agent, running an ERASER Engine prior to 119.1.7.8, may be susceptible to an Elevation of Privilege vulnerability, which may allow an attacker to delete resources that are normally pr...Show more |
1Broadcom 1Fabric Operating System Jun 17, 2026 Apr 24, 2025 8.6 HIGH· v4 6.7 MEDIUM· v3 N/A· v2 Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can potentially execute arbitrary code with full root privileges on Fabric OS versions 9.1.0 through 9.1...Show more |
2Broadcom Brocade2Active Support Connectivity Gateway Brocade Active Support Connectivity GatewayJun 17, 2026 Feb 28, 2025 7.6 HIGH· v4 9.1 CRITICAL· v3 N/A· v2 Brocade ASCG before 3.2.0 Web Interface is not enforcing HSTS, as defined by RFC 6797. HSTS is an optional response header that can be configured on the server to instruct the browser to only communicate via HTTPS. T...Show more |
1Broadcom 1Fabric Operating System Jun 17, 2026 Feb 15, 2025 5.3 MEDIUM· v4 7.5 HIGH· v3 N/A· v2 If Brocade Fabric OS before Fabric OS 9.2.0 configuration settings are not set to encrypt SNMP passwords, then the SNMP privsecret / authsecret fields can be exposed in plaintext. The plaintext passwords can be exposed i...Show more |
1Broadcom 1Fabric Operating System Jun 17, 2026 Feb 15, 2025 8.6 HIGH· v4 8.0 HIGH· v3 N/A· v2 Implementation of the Simple Network Management Protocol (SNMP) operating on the Brocade 6547 (FC5022) embedded switch blade, makes internal script calls to system.sh from within the SNMP binary. An authenticated atta...Show more |
Brocade SANnav OVA before SANnav 2.3.1b enables SHA1 deprecated setting for SSH for port 22. |
Brocade SANnav before SANnav 2.3.1b enables weak TLS ciphers on ports 443 and 18082. In case of a successful exploit, an attacker can read Brocade SANnav data stream that includes monitored Brocade Fabric OS switches...Show more |
Docker daemon in Brocade SANnav before SANnav 2.3.1b runs without auditing. The vulnerability could allow a remote authenticated attacker to execute various attacks. |
Under certain error conditions at time of SANnav installation or upgrade, the encryption key can be written into and obtained from a Brocade SANnav supportsave. An attacker with privileged access to the Brocade SANnav d...Show more |
CalInvocationHandler in Brocade SANnav before 2.3.1b logs sensitive information in clear text. The vulnerability could allow an authenticated, local attacker to view Brocade Fabric OS switch sensitive information in c...Show more |
2Broadcom Brocade2Fabric Operating System Fabric Operating SystemJun 17, 2026 Nov 21, 2024 8.5 HIGH· v4 7.8 HIGH· v3 N/A· v2 A command injection vulnerability in Brocade Fabric OS before 9.2.0c, and 9.2.1 through 9.2.1a on IP extension platforms could allow a local authenticated attacker to perform a privileged escalation via crafted use of th...Show more |
1Broadcom 1Fabric Operating System Jun 17, 2026 Nov 21, 2024 5.9 MEDIUM· v4 7.5 HIGH· v3 N/A· v2 Brocade Fabric OS versions before 8.2.3e2, versions 9.0.0 through 9.2.0c, and 9.2.1 through 9.2.1a can capture the SFTP/FTP server password used for a firmware download operation initiated by SANnav or through WebEM i...Show more |
Possible information exposure through log file vulnerability where sensitive fields are recorded in the debug-enabled logs when debugging is turned on in Brocade SANnav before 2.3.0 and 2.2.2a |