PT-2022-6255 · Hitachi · Hitachi Storage Plug-In For Vmware Vcenter

Published

2022-11-17

·

Updated

2023-02-07

·

CVE-2022-4041

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Hitachi Storage Plug-in for VMware vCenter versions 04.8.0 through 04.9.0
Description The issue is related to an Incorrect Privilege Assignment vulnerability, which allows remote authenticated users to cause privilege escalation. This can be exploited by an attacker to elevate their privileges.
Recommendations For versions 04.8.0 through 04.9.0, update to version 04.9.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the Hitachi Storage Plug-in for VMware vCenter to minimize the risk of exploitation.

Fix

Improper Privilege Management

Improper Authentication

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

BDU:2023-00669
CVE-2022-4041

Affected Products

Hitachi Storage Plug-In For Vmware Vcenter