CVE-2023-4324: Broadcom Raid Controller Web Interface

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP Content-Security-Policy headers

Affected products

  • Broadcom Raid Controller Web Interface: version 51.12.0-2779 only

Published 2023-08-15. Last modified 2026-06-17.