Vulnerabilidades en Broadcom

93 resultados
Análisis Vexday

Com 91 CVEs catalogadas, o portfólio da Broadcom apresenta uma taxa de exploração ativa abaixo da média geral do catálogo, sem registros no CISA KEV e sem provas de conceito públicas conhecidas — indicadores que sugerem um nível de pressão ofensiva relativamente contido no momento. Das seis vulnerabilidades de severidade crítica, nenhuma figura em exploração confirmada, embora a ausência de PoC pública não elimine o risco de exploração privada. O tipo de falha mais recorrente é CWE-269 (gerenciamento impróprio de privilégios), o que aponta para uma superfície de ataque concentrada em escalonamento de privilégios e controle de acesso — área que merece atenção especial em ambientes com múltiplos níveis de permissão. A CVE mais perigosa atualmente identificada, CVE-2019-9500, apresenta EPSS de 0,0384, valor modesto, mas sua antiguidade sugere que sistemas sem as devidas correções acumuladas permanecem expostos a um vetor conhecido há anos.

CVE-2025-69270LOWSpectrum session token in URLEPSS 0.3%CVE-2025-32089HIGHDell ControlVault3 CvManager_SBI buffer overflow vulnerabilityEPSS 0.3%CVE-2025-8660MEDIUMPrivilege Escalation in Symantec PGP Encryption 11.0.1EPSS 0.3%CVE-2025-4663MEDIUMDenial-of-Service (DoS) after Unusual or Exceptional Conditions vulnerabilityEPSS 0.3%CVE-2024-38493MEDIUMSymantec Privileged Access Manager Reflected Cross Site Scripting vulnerabilityEPSS 0.3%CVE-2025-69276LOWSpectrum insecure deserialiationEPSS 0.3%CVE-2025-24505HIGHThis vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by uploadiEPSS 0.3%CVE-2025-24501MEDIUMAn improper input validation allows an unauthenticated attacker to alter PAM logs by sending a specially crafted HTTP request.EPSS 0.3%CVE-2024-36457MEDIUMSymantec Privileged Access Manager Authentication Bypass vulnerabilityEPSS 0.3%CVE-2024-38491HIGHSymantec Privileged Access Manager SQL Injection vulnerabilityEPSS 0.3%CVE-2024-38495MEDIUMSymantec Privileged Access Manager User Enumeration vulnerabilityEPSS 0.3%CVE-2025-36553HIGHDell ControlVault3 CvManager buffer overflow vulnerabilityEPSS 0.3%CVE-2025-69274LOWSpectrum broken authorization schemeEPSS 0.3%CVE-2024-38496MEDIUMSymantec Privileged Access Manager Insecure Direct Object Reference vulnerabilityEPSS 0.3%CVE-2025-24506MEDIUMA specific authentication strategy allows to learn ids of PAM users associated with certain authentication types.EPSS 0.2%CVE-2025-6391HIGHJSON Web Token (JWT) Exposure in Log FilesEPSS 0.2%CVE-2025-69271LOWSpectrum basic authentication in useEPSS 0.2%CVE-2025-24503CRITICALA malicious actor can fix the session of a PAM user by tricking the user to click on a specially crafted link to the PAM server.EPSS 0.2%CVE-2025-31649HIGHDell ControlVault3 ControlVault WBDI Driver hard-coded password vulnerabilityEPSS 0.2%CVE-2025-24504MEDIUMAn improper input validation the CSRF filter results in unsanitized user input written to the application logs.EPSS 0.2%