SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in a Storage administrative role are able to access HNAS configuration backup and diagnostic data, that would normally be barred to that specific administrative role.
2023-12-05T00:15:09.840
2024-11-21T08:42:32.017
Modified
CVSSv3.1: 7.6 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | hitachi | vantara_hitachi_network_attached_storage | ≤ 14.8.7825.01 | Yes |
Operating System | microsoft | windows | - | No |