XXE Vulnerability in Hitachi Device Manager and Hitachi Replication Manager
CVE-2017-9295

6.5MEDIUM

Key Information:

Vendor
Hitachi
Vendor
CVE Published:
29 May 2017

Summary

An XML External Entity (XXE) vulnerability exists in Hitachi Device Manager prior to version 8.5.2-01 and Hitachi Replication Manager prior to version 8.5.2-00. This security flaw enables authenticated remote users to exploit the affected software, allowing them to read arbitrary files from the system. Such vulnerabilities can lead to serious data breaches and pose significant risks to users' sensitive information.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.