PT-2024-1075 · Microchip · Maxview Storage Manager

Published

2024-01-07

·

Updated

2025-06-18

·

CVE-2024-22216

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microchip maxView Storage Manager versions 3.00.23484 through 4.14.00.26064 Microchip maxView Storage Manager versions prior to 3.07.23980 Microchip maxView Storage Manager versions prior to 4.07.00.25339
Description The issue is related to the Redfish server in the Microchip maxView Storage Manager, where unauthorized access can occur due to inadequate authorization procedures. This can lead to data modification and information disclosure. The vulnerability can be exploited remotely.
Recommendations For versions 3.00.23484 through 4.14.00.26064, update to version 3.07.23980 or later. For versions prior to 4.07.00.25339, update to version 4.07.00.25339 or later. As a temporary workaround, consider restricting access to the Redfish server until a patch is available.

Fix

Improper Access Control

Incorrect Privilege Assignment

Improper Authorization

Weakness Enumeration

Related Identifiers

BDU:2024-00326
CVE-2024-22216

Affected Products

Maxview Storage Manager