ZeroHour

CVE-2023-5808

CVSS 3.1
6.5 medium
EPSS
<1%p44
Published
()
Modified
Description

SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in a Storage administrative role are able to access HNAS configuration backup and diagnostic data, that would normally be barred to that specific administrative role.

Vendors
hitachi
Products
vantara hitachi network attached storage
Weakness
CWE-285, CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.