SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in a Storage administrative role are able to access HNAS configuration backup and diagnostic data, that would normally be barred to that specific administrative role.
Configurations
Configuration 1 (hide)
| AND |
|
Information
Published : 2023-12-05 00:15
Updated : 2023-12-12 17:15
NVD link : CVE-2023-5808
Mitre link : CVE-2023-5808
JSON object : View
Products Affected
hitachi
- vantara_hitachi_network_attached_storage
microsoft
- windows
CWE
CWE-287
Improper Authentication
