XXE Vulnerability in Hitachi Device Manager and Hitachi Replication Manager
CVE-2017-9295
6.5MEDIUM
Summary
An XML External Entity (XXE) vulnerability exists in Hitachi Device Manager prior to version 8.5.2-01 and Hitachi Replication Manager prior to version 8.5.2-00. This security flaw enables authenticated remote users to exploit the affected software, allowing them to read arbitrary files from the system. Such vulnerabilities can lead to serious data breaches and pose significant risks to users' sensitive information.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved