PT-2023-3689 · Hitachi · Hitachi Device Manager

Published

2023-05-26

·

Updated

2023-07-27

·

CVE-2023-34142

CVSS v3.1

9.0

Critical

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Hitachi Device Manager versions prior to 8.8.5-02
Description The issue is related to the cleartext transmission of sensitive information in Hitachi Device Manager, affecting components such as Device Manager Server, Device Manager Agent, and Host Data Collector. This allows for interception, potentially enabling unauthorized access to protected information.
Recommendations For versions prior to 8.8.5-02, update to version 8.8.5-02 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive information and implementing additional security measures to minimize the risk of interception.

Fix

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

BDU:2023-03976
CVE-2023-34142

Affected Products

Hitachi Device Manager