CVE-2025-69276
Deserialization Vulnerability in Broadcom DX NetOps Spectrum Allows Object Injection
Publication date: 2026-01-12
Last updated on: 2026-01-12
Assigner: CA Technologies - A Broadcom Company
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| broadcom | dx_netops_spectrum | to 24.3.13 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-502 | The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a Deserialization of Untrusted Data issue in Broadcom DX NetOps Spectrum on Windows and Linux. It allows an attacker to perform Object Injection by exploiting the way the software deserializes data from untrusted sources. This affects versions 24.3.13 and earlier.
How can this vulnerability impact me? :
The vulnerability could allow an attacker to inject malicious objects during the deserialization process, potentially leading to unauthorized actions or compromise of the affected system. However, the CVSS score is low (2.3), indicating limited impact or exploitability under certain conditions.