PT-2024-1075 · Microchip · Maxview Storage Manager
Published
2024-01-07
·
Updated
2025-06-18
·
CVE-2024-22216
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microchip maxView Storage Manager versions 3.00.23484 through 4.14.00.26064
Microchip maxView Storage Manager versions prior to 3.07.23980
Microchip maxView Storage Manager versions prior to 4.07.00.25339
Description
The issue is related to the Redfish server in the Microchip maxView Storage Manager, where unauthorized access can occur due to inadequate authorization procedures. This can lead to data modification and information disclosure. The vulnerability can be exploited remotely.
Recommendations
For versions 3.00.23484 through 4.14.00.26064, update to version 3.07.23980 or later.
For versions prior to 4.07.00.25339, update to version 4.07.00.25339 or later.
As a temporary workaround, consider restricting access to the Redfish server until a patch is available.
Fix
Improper Access Control
Incorrect Privilege Assignment
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Maxview Storage Manager