CVE-2023-6538 Information

Description

SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure through URL manipulation. Authenticated users in Storage Server or combined Server+Storage administrative roles are able to access SMU configuration backup that would normally be barred to those specific administrative roles.

Reference

https://knowledge.hitachivantara.com/Security/System_Management_Unit_(SMU)_versions_prior_to_14.8.7825.01%2C_used_to_manage_Hitachi_Vantara_NAS_products_is_susceptible_to_unintended_information_disclosure_via_unprivileged_access_to_SMU_configuration_backup_data.

Share on: