CVE-2023-6538

SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in Storage, Server or combined Server+Storage administrative roles are able to access SMU configuration backup, that would normally be barred to those specific administrative roles.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:hitachi:system_management_unit_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hitachi:system_management_unit:-:*:*:*:*:*:*:*

History

14 Dec 2023, 17:02

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-11 18:15

Updated : 2024-02-28 20:54


NVD link : CVE-2023-6538

Mitre link : CVE-2023-6538

CVE.ORG link : CVE-2023-6538


JSON object : View

Products Affected

hitachi

  • system_management_unit
  • system_management_unit_firmware
CWE
NVD-CWE-Other CWE-285

Improper Authorization