vendor:
Hitachi NAS (HNAS) System Management Unit (SMU)
by:
Arslan Masood
5.1
CVSS
MEDIUM
Insecure Direct Object Reference (IDOR)
285
CWE
Product Name: Hitachi NAS (HNAS) System Management Unit (SMU)
Affected Version From: Version < 14.8.7825.01
Affected Version To: Version 14.8.7825.01
Patch Exists: NO
Related CWE: CVE-2023-5808
CPE: a:hitachi:hitachi_nas
Platforms Tested:
2023
Hitachi NAS (HNAS) System Management Unit (SMU) Backup & Restore IDOR Vulnerability
The Hitachi NAS (HNAS) System Management Unit (SMU) before version 14.8.7825.01 is vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability. An attacker could exploit this vulnerability to access unauthorized backup and restore functionalities.
Mitigation:
To mitigate this vulnerability, it is recommended to update the Hitachi NAS (HNAS) System Management Unit (SMU) to version 14.8.7825.01 or later to prevent unauthorized access.