CVE-2025-10847: Broadcom Unified Infrastructure Management

High severity, CVSS 8.4. EPSS: 0.5% chance of exploitation in the next 30 days.

DX Unified Infrastructure Management (Nimsoft/UIM) and below contains an improper ACL handling vulnerability in the robot (controller) component. A remote attacker can execute commands, read from, or write to the target system.

Affected products

  • Broadcom Unified Infrastructure Management: version 23.4.5 only

Published 2025-10-01. Last modified 2026-10-09.