Broadcom DX NetOps Spectrum
cpe:2.3:a:broadcom:dx_netops_spectrum:*:*:*:*:*:*:*
- <= 23.3.6
A command injection vulnerability has been identified in Broadcom DX NetOps Spectrum versions through 23.3.6 on both Windows and Linux platforms. This vulnerability allows attackers to execute arbitrary commands on the host operating system with the same privileges as the vulnerable application, specifically within the Network Configuration Manager (NCM) service.
Exploitation of this vulnerability could lead to unauthorized execution of commands on the host operating system, potentially allowing for further exploitation or manipulation of the system.
Users can upgrade to Broadcom DX NetOps Spectrum version 25.4.1 or later to address this vulnerability. Instructions for upgrading can be found in the Broadcom Product Notifications.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.