In default installations of Microchip maxView Storage Manager (for Adaptec Smart Storage Controllers) where Redfish server is configured for remote system management, unauthorized access can occur, with data modification and information disclosure. This affects 3.00.23484 through 4.14.00.26064 (except for the patched versions 3.07.23980 and 4.07.00.25339).
References
Configurations
History
21 Nov 2024, 08:55
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.microchip.com/en-us/solutions/embedded-security/how-to-report-potential-product-security-vulnerabilities/maxview-storage-manager-redfish-server-vulnerability - Vendor Advisory |
15 Feb 2024, 20:09
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 10.0 |
11 Jan 2024, 16:44
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:microchip:maxview_storage_manager:*:*:*:*:*:-:*:* | |
References | () https://www.microchip.com/en-us/solutions/embedded-security/how-to-report-potential-product-security-vulnerabilities/maxview-storage-manager-redfish-server-vulnerability - Vendor Advisory | |
CWE | NVD-CWE-noinfo | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
First Time |
Microchip
Microchip maxview Storage Manager |
08 Jan 2024, 07:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-01-08 07:15
Updated : 2024-11-21 08:55
NVD link : CVE-2024-22216
Mitre link : CVE-2024-22216
CVE.ORG link : CVE-2024-22216
JSON object : View
Products Affected
microchip
- maxview_storage_manager
CWE