CVE-2023-6538

SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in Storage, Server or combined Server+Storage administrative roles are able to access SMU configuration backup, that would normally be barred to those specific administrative roles.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:hitachi:system_management_unit_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hitachi:system_management_unit:-:*:*:*:*:*:*:*

History

14 Dec 2023, 17:02

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.6
v2 : unknown
v3 : 6.5
CPE cpe:2.3:o:hitachi:system_management_unit_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hitachi:system_management_unit:-:*:*:*:*:*:*:*
CWE NVD-CWE-Other
First Time Hitachi system Management Unit
Hitachi system Management Unit Firmware
Hitachi
References () https://knowledge.hitachivantara.com/Security/System_Management_Unit_(SMU)_versions_prior_to_14.8.7825.01%2C_used_to_manage_Hitachi_Vantara_NAS_products_is_susceptible_to_unintended_information_disclosure_via_unprivileged_access_to_SMU_configuration_backup_data. - () https://knowledge.hitachivantara.com/Security/System_Management_Unit_(SMU)_versions_prior_to_14.8.7825.01%2C_used_to_manage_Hitachi_Vantara_NAS_products_is_susceptible_to_unintended_information_disclosure_via_unprivileged_access_to_SMU_configuration_backup_data. - Vendor Advisory

12 Dec 2023, 17:15

Type Values Removed Values Added
References
  • {'url': 'https://knowledge.hitachivantara.com/Security/System_Management_Unit_(SMU)_versions_prior_to_14.8.7825.01%2C_used_to_manage_Hitachi_Vantara_NAS_products_is_susceptible_to_unintended_information_disclosure_via_unprivileged_access_to_SMU_configuration_backup_data', 'source': 'security.vulnerabilities@hitachivantara.com'}
  • () https://knowledge.hitachivantara.com/Security/System_Management_Unit_(SMU)_versions_prior_to_14.8.7825.01%2C_used_to_manage_Hitachi_Vantara_NAS_products_is_susceptible_to_unintended_information_disclosure_via_unprivileged_access_to_SMU_configuration_backup_data. -

12 Dec 2023, 13:43

Type Values Removed Values Added
Summary
  • (es) Las versiones de SMU anteriores a 14.8.7825.01 son susceptibles a la divulgación de información no intencionada mediante la manipulación de URL. Los usuarios autenticados en funciones administrativas de Almacenamiento, Servidor o combinadas de Servidor+Almacenamiento pueden acceder a la copia de seguridad de la configuración de SMU, que normalmente estaría prohibida para esas funciones administrativas específicas.

11 Dec 2023, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-11 18:15

Updated : 2023-12-14 17:02


NVD link : CVE-2023-6538

Mitre link : CVE-2023-6538

CVE.ORG link : CVE-2023-6538


JSON object : View

Products Affected

hitachi

  • system_management_unit_firmware
  • system_management_unit
CWE
NVD-CWE-Other CWE-285

Improper Authorization