Cyber Resilience

CVE-2023-4329

Broadcom Raid Controller Web Interface 51.12.0-2779

Published
15 August 2023
Modified
04 November 2025
Patch / advisory
CVSS Score v3.1 9.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0070 51th percentile
Risk Priority 72 floored blend · peak EPSS

CVSS and EPSS are reproduced from their sources (NVD, FIRST EPSS). Risk Priority is our own derived reading, not an NVD score.

Summary

CVE-2023-4329 is a critical-severity an unspecified weakness vulnerability in Broadcom Raid Controller Web Interface. Its CVSS base score is 9.8 (Critical).

Operationally, ranked in the top 49% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard SESSIONID cookie with SameSite attribute

CWE(s)

Related Threats

CVEs Like This One

CVE-2023-4341Same product: Broadcom Raid Controller Web Interface
CVE-2023-4343Same product: Broadcom Raid Controller Web Interface
CVE-2023-4326Same product: Broadcom Raid Controller Web Interface
CVE-2023-4342Same product: Broadcom Raid Controller Web Interface
CVE-2023-4325Same product: Broadcom Raid Controller Web Interface
CVE-2023-4323Same product: Broadcom Raid Controller Web Interface
CVE-2023-4339Same product: Broadcom Raid Controller Web Interface
CVE-2023-4345Same product: Broadcom Raid Controller Web Interface
CVE-2023-4340Same product: Broadcom Raid Controller Web Interface
CVE-2023-4338Same product: Broadcom Raid Controller Web Interface

Affected Assets

broadcom
raid controller web interface
51.12.0-2779

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References