PT-2024-10165 · Hitachi · Hitachi Ops Center Analyzer+1
Published
2024-10-21
·
Updated
2024-12-19
·
CVE-2024-10205
CVSS v2.0
9.7
Critical
| Vector | AV:N/AC:L/Au:N/C:P/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Hitachi Ops Center Analyzer versions 10.0.0-00 through 11.0.3-00
Hitachi Infrastructure Analytics Advisor versions 2.1.0-00 through 4.4.0-00
Description
The issue is related to an authentication bypass, which may allow a remote attacker to gain unauthorized access to protected information. This is due to a lack of authentication for a critical function in the affected software.
Recommendations
For Hitachi Ops Center Analyzer versions 10.0.0-00 through 11.0.3-00, update to version 11.0.3-00 or later.
For Hitachi Infrastructure Analytics Advisor versions 2.1.0-00 through 4.4.0-00, update to a version later than 4.4.0-00.
As a temporary workaround, consider restricting access to the critical function that lacks authentication until a patch is available.
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hitachi Infrastructure Analytics Advisor
Hitachi Ops Center Analyzer