First published: Mon Dec 11 2023(Updated: )
SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in Storage, Server or combined Server+Storage administrative roles are able to access SMU configuration backup, that would normally be barred to those specific administrative roles.
Credit: security.vulnerabilities@hitachivantara.com Arslan Masood
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Hitachi System Management Unit | <14.8.7825.01 | |
Hitachi System Management Unit |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-6538 has a high severity rating due to the risk of unintended information disclosure.
To remediate CVE-2023-6538, upgrade the Hitachi System Management Unit firmware to version 14.8.7825.01 or later.
Authenticated users with Storage, Server, or combined Server+Storage administrative roles are affected by CVE-2023-6538.
CVE-2023-6538 is classified as an information disclosure vulnerability.
An attacker could gain unauthorized access to sensitive SMU configuration backup data through URL manipulation.