First published: Mon Dec 04 2023(Updated: )
SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in a Storage administrative role are able to access HNAS configuration backup and diagnostic data, that would normally be barred to that specific administrative role.
Credit: security.vulnerabilities@hitachivantara.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Hitachi Vantara Hitachi Network Attached Storage | <=14.8.7825.01 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-5808 is a vulnerability in System Management Unit (SMU) versions prior to 14.8.7825.01 used to manage Hitachi Vantara NAS products.
CVE-2023-5808 allows authenticated users in a Storage administrative role to access HNAS configuration backup and diagnostic data that they should not have access to.
The severity of CVE-2023-5808 is rated as high with a CVSS score of 7.6.
To fix CVE-2023-5808, upgrade to SMU version 14.8.7825.01 or later.
You can find more information about CVE-2023-5808 on the Hitachi Vantara Support website.