Broadcom DX NetOps Spectrum
cpe:2.3:a:broadcom:dx_netops_spectrum:*:*:*:*:*:*:*
- <= 24.3.13
A deserialization vulnerability allowing object injection has been identified in Broadcom DX NetOps Spectrum versions through 24.3.13 on both Windows and Linux. This vulnerability arises from insecure deserialization of user-supplied data, which could be exploited by an authenticated attacker to trigger arbitrary DNS lookups and potentially execute remote code.
Exploitation of this vulnerability could lead to arbitrary DNS lookups and potentially allow for remote code execution.
Users can upgrade to Broadcom DX NetOps Spectrum version 25.4.1 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.