CVE-2019-13657: Broadcom Ca Performance Management

High severity, CVSS 8.8. EPSS: 2.5% chance of exploitation in the next 30 days.

CA Performance Management 3.5.x, 3.6.x before 3.6.9, and 3.7.x before 3.7.4 have a default credential vulnerability that can allow a remote attacker to execute arbitrary commands and compromise system security.

Affected products

  • Broadcom Ca Performance Management: from 3.6.0, before 3.6.9 (fixed in 3.6.9); from 3.7.0, before 3.7.4 (fixed in 3.7.4); version 3.5.0 only
  • Broadcom Network Operations: up to and including 19.1

Published 2019-10-17. Last modified 2026-06-17.