vendor:
Hitachi NAS (HNAS) System Management Unit (SMU)
by:
Arslan Masood
5.1
CVSS
MEDIUM
Insecure Direct Object Reference (IDOR)
862
CWE
Product Name: Hitachi NAS (HNAS) System Management Unit (SMU)
Affected Version From: < 14.8.7825.01
Affected Version To: Unknown
Patch Exists: YES
Related CWE: CVE-2023-5808
CPE: -
Platforms Tested: Unknown
2023
Hitachi NAS (HNAS) System Management Unit (SMU) Backup & Restore IDOR Vulnerability
The Hitachi NAS (HNAS) System Management Unit (SMU) before version 14.8.7825.01 is vulnerable to an Insecure Direct Object Reference (IDOR) issue. An attacker can exploit this vulnerability to download arbitrary files from the server. This vulnerability has been assigned CVE-2023-5808.
Mitigation:
To mitigate this vulnerability, it is recommended to update the Hitachi NAS (HNAS) System Management Unit (SMU) to version 14.8.7825.01 or later. Additionally, restrict access to the SMU interface to authorized users only.