PT-2023-3688 · Hitachi · Hitachi Device Manager

Published

2023-05-26

·

Updated

2023-07-27

·

CVE-2023-34143

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Hitachi Device Manager versions prior to 8.8.5-02
Description The issue is related to improper validation of certificates with host mismatch in Hitachi Device Manager, which can allow a Man in the Middle Attack. This can be exploited by a remote attacker. The vulnerability affects the Device Manager Server, Device Manager Agent, and Host Data Collector components.
Recommendations For versions prior to 8.8.5-02, update to version 8.8.5-02 or later to resolve the issue. As a temporary workaround, consider restricting the use of SSL/TLS certificates to minimize the risk of exploitation. Additionally, ensure that all connections to the Device Manager components are properly validated to prevent Man in the Middle Attacks.

Fix

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

BDU:2023-03974
CVE-2023-34143

Affected Products

Hitachi Device Manager