CVE-2023-5808: System Management Unit (SMU) versions prior to 14.8.7825.01, used to manage Hitachi Vantara NAS products are susceptible to unintended information disclosure via unprivileged access to HNAS configuration backup and diagnostic data.
SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in a Storage administrative role are able to access HNAS configuration backup and diagnostic data, that would normally be barred to that specific administrative role.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-5808?
CVE-2023-5808 is a vulnerability in System Management Unit (SMU) versions prior to 14.8.7825.01 used to manage Hitachi Vantara NAS products.
How does CVE-2023-5808 impact the affected software?
CVE-2023-5808 allows authenticated users in a Storage administrative role to access HNAS configuration backup and diagnostic data that they should not have access to.
What is the severity of CVE-2023-5808?
The severity of CVE-2023-5808 is rated as high with a CVSS score of 7.6.
How can I fix CVE-2023-5808?
To fix CVE-2023-5808, upgrade to SMU version 14.8.7825.01 or later.
Where can I find more information about CVE-2023-5808?
You can find more information about CVE-2023-5808 on the Hitachi Vantara Support website.