CVE-2023-4336: Broadcom Raid Controller Web Interface

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard cookies with Secure attribute

Affected products

  • Broadcom Raid Controller Web Interface: version 51.12.0-2779 only

Published 2023-08-15. Last modified 2026-06-17.