PT-2024-1273 · Hitachi · Hitachi Tuning Manager

Published

2024-01-15

·

Updated

2024-01-22

·

CVE-2023-6457

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Hitachi Tuning Manager versions prior to 8.8.5-04
Description The issue is related to incorrect default permissions in the Hitachi Tuning Manager server component on Windows, allowing local users to read and write specific files. This can be exploited by an attacker to access sensitive data.
Recommendations For versions prior to 8.8.5-04, update to version 8.8.5-04 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation.

Fix

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

BDU:2024-00699
CVE-2023-6457

Affected Products

Hitachi Tuning Manager