Cyber Resilience

CVE-2023-4336

Broadcom Raid Controller Web Interface 51.12.0-2779

Published
15 August 2023
Modified
04 November 2025
Patch / advisory
CVSS Score v3.1 9.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0059 45th percentile
Risk Priority 72 floored blend · peak EPSS

Summary

CVE-2023-4336 is a critical-severity an unspecified weakness vulnerability in Broadcom Raid Controller Web Interface. Its CVSS base score is 9.8 (Critical).

Operationally, ranked at the 45th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard cookies with Secure attribute

CWE(s)

Related Threats

CVEs Like This One

CVE-2023-4331Same product: Broadcom Raid Controller Web Interface
CVE-2023-4337Same product: Broadcom Raid Controller Web Interface
CVE-2023-4334Same product: Broadcom Raid Controller Web Interface
CVE-2023-4345Same product: Broadcom Raid Controller Web Interface
CVE-2023-4326Same product: Broadcom Raid Controller Web Interface
CVE-2023-4339Same product: Broadcom Raid Controller Web Interface
CVE-2023-4325Same product: Broadcom Raid Controller Web Interface
CVE-2023-4323Same product: Broadcom Raid Controller Web Interface
CVE-2023-4342Same product: Broadcom Raid Controller Web Interface
CVE-2023-4324Same product: Broadcom Raid Controller Web Interface

Affected Assets

broadcom
raid controller web interface
51.12.0-2779

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References