SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in Storage, Server or combined Server+Storage administrative roles are able to access SMU configuration backup, that would normally be barred to those specific administrative roles.
2023-12-11T18:15:30.250
2024-11-21T08:44:03.497
Modified
CVSSv3.1: 7.6 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | hitachi | system_management_unit_firmware | < 14.8.7825.01 | Yes |
Hardware | hitachi | system_management_unit | - | No |