Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Broadcom — Vulnerabilities & Security Advisories 93

Browse all 93 CVE security advisories affecting Broadcom. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Broadcom operates as a global infrastructure technology leader, specializing in semiconductor and infrastructure software solutions that power critical enterprise networks, data centers, and broadband connectivity. Its extensive product portfolio, including VMware virtualization and network switching hardware, creates a broad attack surface for potential exploitation. Historically, vulnerabilities within its ecosystem have frequently involved remote code execution, buffer overflows, and privilege escalation flaws, often stemming from complex legacy codebases or misconfigured default settings in embedded systems. Notable security incidents have included critical flaws in network management interfaces and firmware components, which could allow attackers to gain unauthorized access or disrupt service availability. With 88 recorded CVEs, the company’s security posture is heavily scrutinized due to the critical nature of its infrastructure role. Continuous patching and rigorous code auditing remain essential to mitigate risks associated with these diverse software and hardware components in high-stakes environments.

CVE ID Title CVSS Severity Published
CVE-2026-15380 Local privilege escalation in Symantec ITMS — Symantec Management Suite - - 2026-07-17
CVE-2026-15379 Arbitrary File Read as SYSTEM in Symantec ITMS — Symantec IT Management Suite - - 2026-07-17
CVE-2026-11626 Local Privilege Escalation in Symantec Endpoint Protection macOS CleanWipe Removal Tool — Symantec Endpoint Protection CleanWipe Removal Tool CWE-250 - - 2026-06-10
CVE-2026-11815 Insecure Deserialization via MITM in Layer 7 Policy Manager — Layer 7 API Gateway CWE-502 - - 2026-06-10
CVE-2026-8370 Automic Automation Agent Unix privilege escalation — Automic Automation CWE-250 - - 2026-05-19
CVE-2026-3991 Elevation of Privileges in Symantec Data Loss Prevention Windows Endpoint — Data Loss Prevention CWE-829 7.8 High 2026-03-30
CVE-2026-3862 Cross-Site Scripting Vulnerability in SiteMinder Administrative UI — SiteMinder 6.1AI Medium AI 2026-03-10
CVE-2025-13919 Component Object Model (COM) Hijacking in Symantec Endpoint Protection Windows Client — Symantec Endpoint Protection Windows Client CWE-427 4.4 Medium 2026-01-28
CVE-2025-13918 Elevation of Privileges in Symantec Endpoint Protection Windows Client — Symantec Endpoint Protection Windows Client CWE-269 6.7 Medium 2026-01-28
CVE-2025-13917 Elevation of Privileges in Web Security Services (WSS) Agent — Symantec Web Security Services Agent CWE-269 7.0 High 2026-01-28
CVE-2025-69276 Spectrum insecure deserialiation — DX NetOps Spectrum CWE-502 9.8AI Critical AI 2026-01-12
CVE-2025-69275 Spectrum outdated java library in class-path — DX NetOps Spectrum CWE-1395 6.1AI Medium AI 2026-01-12
CVE-2025-69274 Spectrum broken authorization scheme — DX NetOps Spectrum CWE-639 7.8AI High AI 2026-01-12
CVE-2025-69273 Spectrum broken authentication — DX NetOps Spectrum CWE-287 9.8AI Critical AI 2026-01-12
CVE-2025-69272 Spectrum password returned in clear — DX NetOps Spectrum CWE-319 5.9AI Medium AI 2026-01-12
CVE-2025-69271 Spectrum basic authentication in use — DX NetOps Spectrum CWE-522 8.1AI High AI 2026-01-12
CVE-2025-69270 Spectrum session token in URL — DX NetOps Spectrum CWE-598 8.1AI High AI 2026-01-12
CVE-2025-69269 Spectrum command injection in NCM service — DX NetOps Spectrum CWE-78 8.8AI High AI 2026-01-12
CVE-2025-69268 Spectrum reflected XSS — DX NetOps Spectrum CWE-79 6.1AI Medium AI 2026-01-12
CVE-2025-69267 Spectrum directory path traversal — DX NetOps Spectrum CWE-22 6.5AI Medium AI 2026-01-12
CVE-2025-31649 Dell ControlVault3 ControlVault WBDI Driver hard-coded password vulnerability — BCM5820X CWE-908 8.7 High 2025-11-17
CVE-2025-31361 Dell ControlVault3 ControlVault WBDI Driver Broadcom Storage Adapter privilege escalation vulnerability — BCM5820X CWE-908 8.7 High 2025-11-17
CVE-2025-36463 Dell ControlVault3 ControlVault WBDI Driver Broadcom Storage Adapter out-of-bounds write vulnerability — BCM5820X CWE-805 7.3 High 2025-11-17
CVE-2025-36462 Dell ControlVault3 ControlVault WBDI Driver Broadcom Storage Adapter out-of-bounds write vulnerability — BCM5820X CWE-805 7.3 High 2025-11-17
CVE-2025-36461 Dell ControlVault3 ControlVault WBDI Driver Broadcom Storage Adapter out-of-bounds write vulnerability — BCM5820X CWE-805 7.3 High 2025-11-17
CVE-2025-36460 Dell ControlVault3 ControlVault WBDI Driver Broadcom Storage Adapter out-of-bounds write vulnerability — BCM5820X CWE-805 7.3 High 2025-11-17
CVE-2025-32089 Dell ControlVault3 CvManager_SBI buffer overflow vulnerability — BCM5820X CWE-120 8.8 High 2025-11-17
CVE-2025-36553 Dell ControlVault3 CvManager buffer overflow vulnerability — BCM5820X CWE-120 8.8 High 2025-11-17
CVE-2025-10847 DX UIM Probe Improper ACL Handling RCE — Unified Infrastructure Management 9.8AI Critical AI 2025-10-01
CVE-2025-9059 Elevation of Privileges Vulnerability in IT Management Suite — 8.6.IT Management Suite CWE-427 7.8AI High AI 2025-09-11

This page lists every published CVE security advisory associated with Broadcom. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.