SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-6538

SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation.

MEDIUM 6.5EPSS 1.58%

Does this matter?

Lower severity and a low EPSS score (1.58%). Track it; it rarely justifies an emergency change on its own.

Description

SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in Storage, Server or combined Server+Storage administrative roles are able to access SMU configuration backup, that would normally be barred to those specific administrative roles.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
1.58% probability · 74th percentile
CISA KEV
Not listed
Weakness
CWE-285
Affected
hitachi/system management unit firmware
Source
security.vulnerabilities@hitachivantara.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.