CVE-2023-5808

SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in a Storage administrative role are able to access HNAS configuration backup and diagnostic data, that would normally be barred to that specific administrative role.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:hitachi:vantara_hitachi_network_attached_storage:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-12-05 00:15

Updated : 2023-12-12 17:15


NVD link : CVE-2023-5808

Mitre link : CVE-2023-5808

CVE.ORG link : CVE-2023-5808


JSON object : View

Products Affected

microsoft

  • windows

hitachi

  • vantara_hitachi_network_attached_storage
CWE
CWE-287

Improper Authentication

CWE-285

Improper Authorization