vendor:
Hitachi NAS (HNAS) System Management Unit (SMU)
by:
Arslan Masood
5.1
CVSS
MEDIUM
Insecure Direct Object Reference (IDOR)
862
CWE
Product Name: Hitachi NAS (HNAS) System Management Unit (SMU)
Affected Version From: < 14.8.7825.01
Affected Version To: Unknown
Patch Exists: YES
Related CWE: CVE-2023-5808
CPE: a:hitachi:hitachi_nas
Platforms Tested:
2023
Hitachi NAS (HNAS) System Management Unit (SMU) Backup & Restore IDOR Vulnerability
The vulnerability allows an attacker to download arbitrary files from the Hitachi NAS (HNAS) System Management Unit (SMU) due to improper access controls. This vulnerability has been assigned CVE-2023-5808. An exploit script has been created by Arslan Masood (@arszilla) to demonstrate the issue. The affected version is < 14.8.7825.01, and the exploit has been tested on version 13.9.7021.04. By manipulating the JSESSIONID and JSESSIONIDSSO cookies, an attacker can download sensitive files from the system.
Mitigation:
To mitigate this vulnerability, it is recommended to update the Hitachi NAS (HNAS) System Management Unit (SMU) to version 14.8.7825.01 or later. Additionally, restrict access to the SMU interface and ensure proper session management to prevent unauthorized file downloads.