Broadcom Security Vulnerabilities (CVEs)
Track 119 security vulnerabilities affecting Broadcom products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.
This vulnerability allows local authenticated users on Brocade Fabric OS systems to escalate their privileges to root level using specific commands. I...
Feb 3, 2026This vulnerability in Brocade Fabric OS allows authenticated administrators to abuse shell commands (source, ping6, sleep, disown, wait) to manipulate...
Feb 3, 2026This vulnerability allows authenticated administrators on Brocade Fabric OS to use the 'grep' shell command for directory traversal, potentially acces...
Feb 3, 2026This vulnerability in Brocade Fabric OS allows authenticated local attackers with Bash shell access to read insecurely stored file contents, including...
Feb 3, 2026This vulnerability in Brocade Fabric OS allows authenticated remote attackers with administrative credentials to execute arbitrary commands as root us...
Feb 3, 2026This vulnerability allows administrator-level users on Brocade Fabric OS to execute the bind command, enabling privilege escalation and bypassing secu...
Feb 3, 2026This vulnerability in Brocade Fabric OS allows local authenticated users with lower privileges to view command line passwords and access sensitive inf...
Feb 3, 2026A vulnerability in Brocade SANnav migration scripts before version 3.0 allows sensitive database information to be captured in support save files. Att...
Feb 3, 2026A vulnerability in Brocade SANnav's update-reports-purge-settings.sh script logs the database password to system audit logs. This allows authenticated...
Feb 3, 2026Brocade SANnav versions before 2.4.0b log the Fabric OS Switch admin password in clear text within support save logs and heap dump files during out-of...
Feb 2, 2026This vulnerability exposes the Password-Based Encryption (PBE) key in plaintext within system audit logs during migration operations in Brocade SANnav...
Feb 2, 2026CVE-2025-69271 is an insufficient credential protection vulnerability in Broadcom DX NetOps Spectrum that allows attackers to sniff network traffic an...
Jan 12, 2026Broadcom DX NetOps Spectrum transmits sensitive information without encryption, allowing attackers on the same network to intercept credentials, confi...
Jan 12, 2026This vulnerability allows attackers to bypass authentication mechanisms in Broadcom DX NetOps Spectrum, potentially gaining unauthorized access to net...
Jan 12, 2026An authorization bypass vulnerability in Broadcom DX NetOps Spectrum allows attackers to escalate privileges by manipulating user-controlled keys. Thi...
Jan 12, 2026This vulnerability allows attackers to execute arbitrary JavaScript in the context of a user's browser session through DOM-based cross-site scripting ...
Jan 12, 2026A deserialization vulnerability in Broadcom DX NetOps Spectrum allows attackers to inject malicious objects by sending untrusted data to the applicati...
Jan 12, 2026This is a reflected cross-site scripting (XSS) vulnerability in Broadcom DX NetOps Spectrum that allows attackers to inject malicious scripts into web...
Jan 12, 2026This OS command injection vulnerability in Broadcom DX NetOps Spectrum allows attackers to execute arbitrary operating system commands on affected sys...
Jan 12, 2026This vulnerability in Broadcom DX NetOps Spectrum exposes sensitive information through query strings in GET requests, allowing attackers to hijack us...
Jan 12, 2026This path traversal vulnerability in Broadcom DX NetOps Spectrum allows attackers to access files outside the intended directory by manipulating file ...
Jan 12, 2026A heap buffer overflow vulnerability in tcpliveplay utility of tcpreplay 4.5.1 allows attackers to cause denial of service by processing a malicious p...
Sep 23, 2025A double free vulnerability in tcpreplay's tcprewrite allows local attackers to cause denial of service through memory corruption by providing a speci...
Sep 22, 2025CVE-2025-9386 is a use-after-free vulnerability in tcpreplay's tcprewrite component that allows local attackers to potentially execute arbitrary code ...
Aug 24, 2025A use-after-free vulnerability in tcpreplay's tcprewrite component allows local attackers to potentially crash the application or execute arbitrary co...
Aug 24, 2025CVE-2025-8660 is a critical privilege escalation vulnerability in Broadcom software that allows authenticated users to gain elevated privileges beyond...
Aug 11, 2025Brocade SANnav versions before 2.4.0a log passwords and PBE keys in local server audit logs under specific conditions. This allows server administrato...
Jul 10, 2025RabbitMQ versions 3.13.7 and prior log HTTP API authorization headers containing base64-encoded credentials in plaintext. This allows attackers with a...
Jun 19, 2025A path traversal vulnerability in Brocade Fabric OS allows local admin users to access files outside intended directories, potentially exposing sensit...
Jun 19, 2025VMware NSX Manager UI has a stored XSS vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users. This affe...
Jun 4, 2025VMware NSX contains a stored Cross-Site Scripting vulnerability in the router port due to improper input validation. This allows authenticated attacke...
Jun 4, 2025CVE-2024-22654 is an infinite loop vulnerability in tcpreplay's tcprewrite function that can cause denial of service. Attackers can craft malicious pa...
May 29, 2025This vulnerability allows unauthenticated access to PostgreSQL databases in Bitnami's pgpool Docker image and postgres-ha Kubernetes chart. Attackers ...
May 13, 2025This CVE describes an Elevation of Privilege vulnerability in Symantec Endpoint Protection Windows Agent's ERASER Engine that allows attackers to dele...
Apr 30, 2025This vulnerability allows local admin users on Brocade Fabric OS to escalate privileges to root level, enabling arbitrary code execution. It affects F...
Apr 24, 2025Brocade SANnav versions before 2.3.1b enable weak TLS ciphers on ports 443 and 18082, allowing attackers to intercept and read network traffic contain...
Feb 15, 2025This vulnerability allows attackers to perform man-in-the-middle attacks against SSH connections to Brocade SANnav OVA appliances by exploiting the us...
Feb 15, 2025The Docker daemon in Brocade SANnav management software versions before 2.3.1b runs without auditing enabled. This allows remote authenticated attacke...
Feb 14, 2025During SANnav installation or upgrade error conditions, the encryption key can be written to and retrieved from a supportsave file. Attackers with pri...
Feb 14, 2025Brocade SANnav versions before 2.3.1b log sensitive information like passwords and SNMP secrets in clear text. This allows authenticated local attacke...
Feb 14, 2025A command injection vulnerability in Brocade Fabric OS allows local authenticated attackers to escalate privileges via crafted portcfg commands. This ...
Nov 21, 2024Brocade SANnav versions before 2.2.2 log switch passwords in plaintext when debugging is enabled. This allows attackers with access to logs to obtain ...
Nov 21, 2024Brocade SANnav management software versions before 2.2.2 support weak key exchange algorithms on multiple ports, allowing attackers to potentially dec...
Nov 21, 2024This vulnerability allows man-in-the-middle attackers to forge SSH keys during remote operations, enabling them to hijack service sessions on Brocade ...
Nov 12, 2024A reflected cross-site scripting (XSS) vulnerability in the PAM UI web interface allows remote attackers to execute arbitrary JavaScript in users' bro...
Jul 15, 2024CVE-2024-3596 allows a local attacker to forge RADIUS protocol responses by exploiting MD5 collisions, enabling them to modify authentication outcomes...
Jul 9, 2024A vulnerability in Brocade Fabric OS allows authenticated remote attackers to read device data via SNMP using hard-coded default community strings. Th...
Jun 26, 2024This vulnerability in Brocade Fabric OS web interface exposes encoded session passwords in session storage on Virtual Fabric platforms. It allows auth...
Jun 26, 2024This vulnerability exposes Kafka services on the WAN interface of Brocade SANnav management software, allowing unauthenticated attackers to perform de...
Apr 25, 2024Brocade SANnav versions before 2.3.0 transmit syslog traffic in clear text without encryption. This allows unauthenticated remote attackers to interce...
Apr 25, 2024Why Monitor Broadcom Security Vulnerabilities?
Real-time CVE tracking: Our automated system monitors 119+ known vulnerabilities affecting Broadcom products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.
Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Broadcom packages in under 60 seconds. No agents required - completely agentless scanning that works across Broadcom deployments.
Free vulnerability database: Access detailed information about every Broadcom CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.
🚀 Get Started in 60 Seconds
- Register free account & add your servers
- Run one-time scan or schedule automatic monitoring (every 1-24 hours)
- Receive instant alerts when new Broadcom CVEs affect your systems
- Access dashboard with severity breakdown & fix instructions