File and Directory Permission Vulnerability in Hitachi Command Suite

CVE-2020-36695
6.6MEDIUM

Key Information

Vendor
Hitachi
Status
Hitachi Device Manager
Hitachi Tiered Storage Manager
Hitachi Replication Manager
Hitachi Tuning Manager
Vendor
CVE Published:
18 July 2023

Summary

Incorrect Default Permissions vulnerability in Hitachi Device Manager on Linux (Device Manager Server component), Hitachi Tiered Storage Manager on Linux, Hitachi Replication Manager on Linux, Hitachi Tuning Manager on Linux (Hitachi Tuning Manager server, Hitachi Tuning Manager - Agent for RAID, Hitachi Tuning Manager - Agent for NAS components), Hitachi Compute Systems Manager on Linux allows File Manipulation.This issue affects Hitachi Device Manager: before 8.8.5-02; Hitachi Tiered Storage Manager: before 8.8.5-02; Hitachi Replication Manager: before 8.8.5-02; Hitachi Tuning Manager: before 8.8.5-02; Hitachi Compute Systems Manager: before 8.8.3-08.

Affected Version(s)

Hitachi Device Manager < 8.8.5-02

Hitachi Tiered Storage Manager < 8.8.5-02

Hitachi Replication Manager < 8.8.5-02

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Risk change from: 7.8 to: 6.6 - (MEDIUM)

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database
.