CVE-2023-4338: Broadcom Raid Controller Web Interface

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not provide X-Content-Type-Options Headers

Affected products

  • Broadcom Raid Controller Web Interface: version 51.12.0-2779 only

Published 2023-08-15. Last modified 2026-06-17.