Carbon Black Cloud Workload Protection Security Advisory for CVE-2025-2834
Summary
Broadcom's Enterprise Security Group has released an update to address issue that was discovered in the Carbon Black Cloud Workload Protection (CWP) Appliance product.
Affected Product(s)
|
Carbon Black Cloud Workload Protection (CWP) Appliance |
||
|
CVE |
Affected Version(s) |
Remediation |
|
CVE-2025-2834 |
Prior to Carbon Black CWP 1.3.1 |
Download the CWP Appliance v1.3.1 from the Broadcom Download Center. Please refer to Product Download Help for details. |
Issue Details
|
CVE-2025-2834 |
|
|
Severity/CVSSv3: |
Medium / 5.3 AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
|
References: Impact: |
NVD: CVE-2025-2834 TLS Validation Flaw |
|
Description: |
Carbon Black Cloud Workload Protection Appliance, with a version prior to 1.3.1, may be susceptible to an TLS Validation Flaw, potentially enabling a man-in-the-middle (MiTM) attack. |
Mitigation & Additional Information
Carbon Black Cloud Workload Appliance v.1.3.1 has been released which addresses this issue and is available via the Broadcom Download Center. Please refer to the Product Download Help for details..
Broadcom's Enterprise Security Group recommends the following measures to reduce risk of attack:
- Restrict access to administrative or management systems to authorized privileged users.
- Restrict remote access to trusted/authorized systems only.
- Run under the principle of least privilege, where possible, to limit the impact of potential exploitation.
- Keep all operating systems and applications current with vendor patches.
- Follow a multi-layered approach to security. At a minimum, run both firewall and anti-malware applications to provide multiple points of detection and protection for both inbound and outbound threats.
- Deploy network and host-based intrusion detection systems to monitor network traffic for signs of anomalous or suspicious activity. This may aid in the detection of attacks or malicious activity related to the exploitation of latent vulnerabilities.
Acknowledgements
- CVE-2025-2834: Konrad Porzezynski