PT-2024-2503 · Hitachi · Hitachi Virtual Storage Platform 5600+39

Published

2024-03-24

·

Updated

2024-03-26

·

CVE-2022-36407

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Hitachi Virtual Storage Platform versions prior to DKCMAIN Ver. 70-06-74-00/00, SVP Ver. 70-06-58/00 Hitachi Virtual Storage Platform VP9500 versions prior to DKCMAIN Ver. 70-06-74-00/00, SVP Ver. 70-06-58/00 Hitachi Virtual Storage Platform G1000, G1500 versions prior to DKCMAIN Ver. 80-06-92-00/00, SVP Ver. 80-06-87/00 Hitachi Virtual Storage Platform F1500 versions prior to DKCMAIN Ver. 80-06-92-00/00, SVP Ver. 80-06-87/00 Hitachi Virtual Storage Platform 5100, 5500, 5100H, 5500H versions prior to DKCMAIN Ver. 90-08-81-00/00, SVP Ver. 90-08-81/00 Hitachi Virtual Storage Platform 5200, 5600, 5200H, 5600H versions prior to DKCMAIN Ver. 90-08-81-00/00, SVP Ver. 90-08-81/00 Hitachi Unified Storage VM versions prior to DKCMAIN Ver. 73-03-75-X0/00, SVP Ver. 73-03-74/00 Hitachi Virtual Storage Platform G100, G200, G400, G600, G800 versions prior to DKCMAIN Ver. 83-06-19-X0/00, SVP Ver. 83-06-20-X0/00 Hitachi Virtual Storage Platform F400, F600, F800 versions prior to DKCMAIN Ver. 83-06-19-X0/00, SVP Ver. 83-06-20-X0/00 Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900 versions prior to DKCMAIN Ver. 88-08-09-XX/00, SVP Ver. 88-08-11-X0/02 Hitachi Virtual Storage Platform F350, F370, F700, F900 versions prior to DKCMAIN Ver. 88-08-09-XX/00, SVP Ver. 88-08-11-X0/02 Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H versions prior to DKCMAIN Ver. 93-06-81-X0/00, SVP Ver. 93-06-81-X0/00
Description The issue allows local users to gain sensitive information through the insertion of sensitive information into log files. This can be exploited by an attacker to disclose protected information.
Recommendations For Hitachi Virtual Storage Platform versions prior to DKCMAIN Ver. 70-06-74-00/00, SVP Ver. 70-06-58/00, update to a version that includes the fix for this issue. For Hitachi Virtual Storage Platform VP9500 versions prior to DKCMAIN Ver. 70-06-74-00/00, SVP Ver. 70-06-58/00, update to a version that includes the fix for this issue. For Hitachi Virtual Storage Platform G1000, G1500 versions prior to DKCMAIN Ver. 80-06-92-00/00, SVP Ver. 80-06-87/00, update to a version that includes the fix for this issue. For Hitachi Virtual Storage Platform F1500 versions prior to DKCMAIN Ver. 80-06-92-00/00, SVP Ver. 80-06-87/00, update to a version that includes the fix for this issue. For Hitachi Virtual Storage Platform 5100, 5500, 5100H, 5500H versions prior to DKCMAIN Ver. 90-08-81-00/00, SVP Ver. 90-08-81/00, update to a version that includes the fix for this issue. For Hitachi Virtual Storage Platform 5200, 5600, 5200H, 5600H versions prior to DKCMAIN Ver. 90-08-81-00/00, SVP Ver. 90-08-81/00, update to a version that includes the fix for this issue. For Hitachi Unified Storage VM versions prior to DKCMAIN Ver. 73-03-75-X0/00, SVP Ver. 73-03-74/00, update to a version that includes the fix for this issue. For Hitachi Virtual Storage Platform G100, G200, G400, G600, G800 versions prior to DKCMAIN Ver. 83-06-19-X0/00, SVP Ver. 83-06-20-X0/00, update to a version that includes the fix for this issue. For Hitachi Virtual Storage Platform F400, F600, F800 versions prior to DKCMAIN Ver. 83-06-19-X0/00, SVP Ver. 83-06-20-X0/00, update to a version that includes the fix for this issue. For Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900 versions prior to DKCMAIN Ver. 88-08-09-XX/00, SVP Ver. 88-08-11-X0/02, update to a version that includes the fix for this issue. For Hitachi Virtual Storage Platform F350, F370, F700, F900 versions prior to DKCMAIN Ver. 88-08-09-XX/00, SVP Ver. 88-08-11-X0/02, update to a version that includes the fix for this issue. For Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H versions prior to DKCMAIN Ver. 93-06-81-X0/00, SVP Ver. 93-06-81-X0/00, update to a version that includes the fix for this issue.

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

BDU:2024-02484
CVE-2022-36407

Affected Products

Hitachi Unified Storage Vm
Hitachi Virtual Storage Platform
Hitachi Virtual Storage Platform 5100
Hitachi Virtual Storage Platform 5100H
Hitachi Virtual Storage Platform 5200
Hitachi Virtual Storage Platform 5200H
Hitachi Virtual Storage Platform 5500
Hitachi Virtual Storage Platform 5500H
Hitachi Virtual Storage Platform 5600
Hitachi Virtual Storage Platform 5600H
Hitachi Virtual Storage Platform E1090
Hitachi Virtual Storage Platform E390
Hitachi Virtual Storage Platform E390H
Hitachi Virtual Storage Platform E590
Hitachi Virtual Storage Platform E590H
Hitachi Virtual Storage Platform E790
Hitachi Virtual Storage Platform E790H
Hitachi Virtual Storage Platform E990
Hitachi Virtual Storage Platform F1500
Hitachi Virtual Storage Platform F350
Hitachi Virtual Storage Platform F370
Hitachi Virtual Storage Platform F400
Hitachi Virtual Storage Platform F600
Hitachi Virtual Storage Platform F700
Hitachi Virtual Storage Platform F800
Hitachi Virtual Storage Platform F900
Hitachi Virtual Storage Platform G100
Hitachi Virtual Storage Platform G1000
Hitachi Virtual Storage Platform G130
Hitachi Virtual Storage Platform G150
Hitachi Virtual Storage Platform G1500
Hitachi Virtual Storage Platform G200
Hitachi Virtual Storage Platform G350
Hitachi Virtual Storage Platform G370
Hitachi Virtual Storage Platform G400
Hitachi Virtual Storage Platform G600
Hitachi Virtual Storage Platform G700
Hitachi Virtual Storage Platform G800
Hitachi Virtual Storage Platform G900
Hitachi Virtual Storage Platform Vp9500