← Back

Broadcom

broadcom

688 CVEs • 285 products

Products (285)

Click to collapse
Toggle
Tcpreplay
tcpreplay
Sannav
sannav
Inoculateit
inoculateit
Reactor Netty
reactor_netty
Etrust Admin
etrust_admin
Unicenter Tng
unicenter_tng
Total Defense
total_defense
Spring Batch
spring_batch
Adviseit
adviseit
Anti Virus
anti-virus
Siteminder
siteminder
Ehealth
ehealth
Vmware Nsx
vmware_nsx
Messaging
messaging

CVEs (688)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Broadcom
1Tcpreplay
Jun 17, 2026
Aug 24, 2025
1.9 LOW· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability has been found in appneta tcpreplay up to 4.5.1. The impacted element is the function get_l2len_protocol of the file get.c of the component tcprewrite. Such manipulation leads to use after free. The attac...Show more
A vulnerability has been found in appneta tcpreplay up to 4.5.1. The impacted element is the function get_l2len_protocol of the file get.c of the component tcprewrite. Such manipulation leads to use after free. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. Upgrading to version 4.5.2-beta3 is sufficient to resolve this issue. You should upgrade the affected component.Show less
1Broadcom
1Tcpreplay
Jun 17, 2026
Aug 24, 2025
1.9 LOW· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A flaw has been found in appneta tcpreplay up to 4.5.1. The affected element is the function fix_ipv6_checksums of the file edit_packet.c of the component tcprewrite. This manipulation causes use after free. The attack i...Show more
A flaw has been found in appneta tcpreplay up to 4.5.1. The affected element is the function fix_ipv6_checksums of the file edit_packet.c of the component tcprewrite. This manipulation causes use after free. The attack is restricted to local execution. The exploit has been published and may be used. Upgrading to version 4.5.2-beta3 is sufficient to fix this issue. It is advisable to upgrade the affected component.Show less
1Broadcom
1Tcpreplay
Jun 17, 2026
Aug 24, 2025
1.9 LOW· v4
5.5 MEDIUM· v3
1.7 LOW· v2
A vulnerability was detected in appneta tcpreplay up to 4.5.1. Impacted is the function tcpedit_post_args of the file /src/tcpedit/parse_args.c. The manipulation results in null pointer dereference. The attack is only po...Show more
A vulnerability was detected in appneta tcpreplay up to 4.5.1. Impacted is the function tcpedit_post_args of the file /src/tcpedit/parse_args.c. The manipulation results in null pointer dereference. The attack is only possible with local access. The exploit is now public and may be used. Upgrading to version 4.5.2-beta2 is recommended to address this issue. Upgrading the affected component is advised. The vendor explains, that he was "[a]ble to reproduce in 6fcbf03 but not in 4.5.2-beta2".Show less
1Broadcom
1Tcpreplay
Jun 17, 2026
Aug 15, 2025
1.3 LOW· v4
5.9 MEDIUM· v3
2.6 LOW· v2
A vulnerability has been found in tcpreplay 4.5.1. This vulnerability affects the function mask_cidr6 of the file cidr.c of the component tcpprep. The manipulation leads to heap-based buffer overflow. The attack can be i...Show more
A vulnerability has been found in tcpreplay 4.5.1. This vulnerability affects the function mask_cidr6 of the file cidr.c of the component tcpprep. The manipulation leads to heap-based buffer overflow. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The researcher is able to reproduce this with the latest official release 4.5.1 and the current master branch. The code maintainer cannot reproduce this for 4.5.2-beta1. In his reply the maintainer explains that "[i]n that case, this is a duplicate that was fixed in 4.5.2."Show less
1Broadcom
1Symantec Pgp Encryption
Jun 17, 2026
Aug 11, 2025
4.6 MEDIUM· v4
6.1 MEDIUM· v3
N/A· v2
A stored Cross-Site Scripting vulnerability (XSS) occurs when the server does not properly validate or encode the data entered by the user.
1Broadcom
1Symantec Pgp Encryption
Jun 17, 2026
Aug 11, 2025
5.6 MEDIUM· v4
9.8 CRITICAL· v3
N/A· v2
Privilege escalation occurs when a user gets access to more resources or functionality than they are normally allowed.
2Broadcom
Brocade
2Ascg
Brocade Active Support Connectivity Gateway
Jun 17, 2026
Jul 17, 2025
8.6 HIGH· v4
9.1 CRITICAL· v3
N/A· v2
Brocade ASCG before 3.3.0 allows for the use of medium strength cryptography algorithms on internal ports ports 9000 and 8036.
2Broadcom
Brocade
2Ascg
Brocade Active Support Connectivity Gateway
Jun 17, 2026
Jul 17, 2025
7.1 HIGH· v4
9.1 CRITICAL· v3
N/A· v2
Brocade ASCG before 3.3.0 logs JSON Web Tokens (JWT) in log files. An attacker with access to the log files can withdraw the unencrypted tokens with security implications, such as unauthorized access, session hijacki...Show more
Brocade ASCG before 3.3.0 logs JSON Web Tokens (JWT) in log files. An attacker with access to the log files can withdraw the unencrypted tokens with security implications, such as unauthorized access, session hijacking, and information disclosure.Show less
1Broadcom
1Brocade Sannav
Jun 17, 2026
Jul 10, 2025
6.7 MEDIUM· v4
4.4 MEDIUM· v3
N/A· v2
Brocade SANnav before Brocade SANnav 2.4.0a could log database passwords in clear text in audit logs when the daily data dump collector invokes docker exec commands. These audit logs are the local server VM’s audit logs...Show more
Brocade SANnav before Brocade SANnav 2.4.0a could log database passwords in clear text in audit logs when the daily data dump collector invokes docker exec commands. These audit logs are the local server VM’s audit logs and are not controlled by SANnav. These logs are only visible to the server admin of the host server and are not visible to the SANnav admin or any SANnav user.Show less
1Broadcom
1Brocade Sannav
Jun 17, 2026
Jul 10, 2025
5.1 MEDIUM· v4
4.4 MEDIUM· v3
N/A· v2
Brocade SANnav before SANnav 2.4.0a logs passwords and pbe keys in the Brocade SANnav server audit logs after installation and under specific conditions. These audit logs are the local server VM’s audit logs and are not...Show more
Brocade SANnav before SANnav 2.4.0a logs passwords and pbe keys in the Brocade SANnav server audit logs after installation and under specific conditions. These audit logs are the local server VM’s audit logs and are not controlled by SANnav. These logs are only visible to the server admin of the host server and are not visible to the SANnav admin or any SANnav user.Show less
1Broadcom
1Brocade Sannav
Jun 17, 2026
Jul 10, 2025
5.1 MEDIUM· v4
4.4 MEDIUM· v3
N/A· v2
Brocade SANnav before SANnav 2.4.0a logs plaintext passphrases in the Brocade SANnav host server audit logs while executing OpenSSL command using a passphrase from the command line or while providing the passphrase throu...Show more
Brocade SANnav before SANnav 2.4.0a logs plaintext passphrases in the Brocade SANnav host server audit logs while executing OpenSSL command using a passphrase from the command line or while providing the passphrase through a temporary file. These audit logs are the local server VM’s audit logs and are not controlled by SANnav. These logs are only visible to the server admin of the host server and are not visible to the SANnav admin or any SANnav user.Show less
2Broadcom
Brocade
2Fabric Operating System
Fabric Operating System
Jun 17, 2026
Jul 8, 2025
6.8 MEDIUM· v4
4.9 MEDIUM· v3
N/A· v2
An Improper Check for Unusual or Exceptional Conditions vulnerability in Brocade Fabric OS before 9.2.2.a could allow an authenticated, network-based attacker to cause a Denial-of-Service (DoS). The vulnerability is...Show more
An Improper Check for Unusual or Exceptional Conditions vulnerability in Brocade Fabric OS before 9.2.2.a could allow an authenticated, network-based attacker to cause a Denial-of-Service (DoS). The vulnerability is encountered when supportsave is invoked remotely, using ssh command or SANnav inline ssh, and the corresponding ssh session is terminated with Control C (^c ) before supportsave completion. This issue affects Brocade Fabric OS 9.0.0 through 9.2.2Show less
1Broadcom
1Rabbitmq Server
Jun 17, 2026
Jun 19, 2025
6.7 MEDIUM· v4
5.5 MEDIUM· v3
N/A· v2
RabbitMQ is a messaging and streaming broker. In versions 3.13.7 and prior, RabbitMQ is logging authorization headers in plaintext encoded in base64. When querying RabbitMQ api with HTTP/s with basic authentication it cr...Show more
RabbitMQ is a messaging and streaming broker. In versions 3.13.7 and prior, RabbitMQ is logging authorization headers in plaintext encoded in base64. When querying RabbitMQ api with HTTP/s with basic authentication it creates logs with all headers in request, including authorization headers which show base64 encoded username:password. This is easy to decode and afterwards could be used to obtain control to the system depending on credentials. This issue has been patched in version 4.0.8.Show less
1Broadcom
1Fabric Operating System
Jun 17, 2026
Jun 19, 2025
4.8 MEDIUM· v4
2.3 LOW· v3
N/A· v2
A path transversal vulnerability in Brocade Fabric OS 9.1.0 through 9.2.2 could allow a local admin user to gain access to files outside the intended directory potentially leading to the disclosure of sensitive inform...Show more
A path transversal vulnerability in Brocade Fabric OS 9.1.0 through 9.2.2 could allow a local admin user to gain access to files outside the intended directory potentially leading to the disclosure of sensitive information. Note: Admin level privilege is required on the switch in order to exploitShow less
2Broadcom
Vmware
4Cloud Foundation
Telco Cloud InfrastructureTelco Cloud Platform+1 more
Jun 17, 2026
Jun 4, 2025
N/A· v4
5.9 MEDIUM· v3
N/A· v2
VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the router port due to improper input validation.
2Broadcom
Vmware
4Cloud Foundation
Telco Cloud InfrastructureTelco Cloud Platform+1 more
Jun 17, 2026
Jun 4, 2025
N/A· v4
6.9 MEDIUM· v3
N/A· v2
VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the gateway firewall due to improper input validation.
2Broadcom
Vmware
4Cloud Foundation
Telco Cloud InfrastructureTelco Cloud Platform+1 more
Jun 17, 2026
Jun 4, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
VMware NSX Manager UI is vulnerable to a stored Cross-Site Scripting (XSS) attack due to improper input validation.
1Broadcom
1Tcpreplay
Jun 17, 2026
May 29, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
tcpreplay v4.4.4 was discovered to contain an infinite loop via the tcprewrite function at get.c.
1Broadcom
2Bitnami
Bitnami/pgpool
Jun 17, 2026
May 13, 2025
9.4 CRITICAL· v4
7.5 HIGH· v3
N/A· v2
The bitnami/pgpool Docker image, and the bitnami/postgres-ha k8s chart, under default configurations, comes with an 'repmgr' user that allows unauthenticated access to the database inside the cluster. The PGPOOL_SR_CHECK...Show more
The bitnami/pgpool Docker image, and the bitnami/postgres-ha k8s chart, under default configurations, comes with an 'repmgr' user that allows unauthenticated access to the database inside the cluster. The PGPOOL_SR_CHECK_USER is the user that Pgpool itself uses to perform streaming replication checks against nodes, and should not be at trust level. This allows to log into a PostgreSQL database using the repgmr user without authentication. If Pgpool is exposed externally, a potential attacker could use this user to get access to the service. This is also present within the bitnami/postgres-ha Kubernetes Helm chart.Show less
1Broadcom
1Symantec Eraser Engine
Jun 17, 2026
Apr 30, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Symantec Endpoint Protection Windows Agent, running an ERASER Engine prior to 119.1.7.8, may be susceptible to an Elevation of Privilege vulnerability, which may allow an attacker to delete resources that are normally pr...Show more
Symantec Endpoint Protection Windows Agent, running an ERASER Engine prior to 119.1.7.8, may be susceptible to an Elevation of Privilege vulnerability, which may allow an attacker to delete resources that are normally protected from an application or user.Show less