Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-6538

Опубликовано: 11 дек. 2023
Источник: nvd
CVSS3: 7.6
CVSS3: 6.5
EPSS Низкий

Описание

SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in Storage, Server or combined Server+Storage administrative roles are able to access SMU configuration backup, that would normally be barred to those specific administrative roles.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:hitachi:system_management_unit_firmware:*:*:*:*:*:*:*:*
Версия до 14.8.7825.01 (исключая)
cpe:2.3:h:hitachi:system_management_unit:-:*:*:*:*:*:*:*

EPSS

Процентиль: 90%
0.05301
Низкий

7.6 High

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-285
NVD-CWE-Other

Связанные уязвимости

CVSS3: 7.6
github
около 2 лет назад

SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in Storage, Server or combined Server+Storage administrative roles are able to access SMU configuration backup, that would normally be barred to those specific administrative roles.

EPSS

Процентиль: 90%
0.05301
Низкий

7.6 High

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-285
NVD-CWE-Other