CVE-2024-21840: Directory and File Permission Vulnerability in Hitachi Storage Plug-in for VMware vCenter
Incorrect Default Permissions vulnerability in Hitachi Storage Plug-in for VMware vCenter allows local users to read and write specific files.
This issue affects Hitachi Storage Plug-in for VMware vCenter: from 04.0.0 through 04.9.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-21840?
CVE-2024-21840 is considered a medium severity vulnerability due to incorrect default permissions in the Hitachi Storage Plug-in.
How do I fix CVE-2024-21840?
To fix CVE-2024-21840, upgrade to Hitachi Storage Plug-in for VMware vCenter version 04.10.0 or later.
Who is affected by CVE-2024-21840?
CVE-2024-21840 affects local users of Hitachi Storage Plug-in for VMware vCenter versions 04.0.0 through 04.9.2.
What kind of files can be accessed due to CVE-2024-21840?
Due to CVE-2024-21840, local users can read and write specific files that should have restricted access.
Is there a workaround for CVE-2024-21840?
There are no widely recommended workarounds for CVE-2024-21840; upgrading to a secure version is the advised solution.