CVE-2023-4335: Broadcom Raid Controller Web Interface

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

Broadcom RAID Controller Web server (nginx) is serving private server-side files without any authentication on Linux

Affected products

  • Broadcom Raid Controller Web Interface: version 51.12.0-2779 only

Published 2023-08-15. Last modified 2026-06-17.