CVE-2023-6538

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/12/2023
Last modified:
14/12/2023

Description

SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in Storage, Server or combined Server+Storage administrative roles are able to access SMU configuration backup, that would normally be barred to those specific administrative roles.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:hitachi:system_management_unit_firmware:*:*:*:*:*:*:*:* 14.8.7825.01 (excluding)
cpe:2.3:h:hitachi:system_management_unit:-:*:*:*:*:*:*:*