PT-2023-3688 · Hitachi · Hitachi Device Manager

CVE-2023-34143

·

Publicado

2023-05-26

·

Atualizado

2023-07-27

CVSS v3.1

8.1

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Hitachi Device Manager versions prior to 8.8.5-02
Description The issue is related to improper validation of certificates with host mismatch in Hitachi Device Manager, which can allow a Man in the Middle Attack. This can be exploited by a remote attacker. The vulnerability affects the Device Manager Server, Device Manager Agent, and Host Data Collector components.
Recommendations For versions prior to 8.8.5-02, update to version 8.8.5-02 or later to resolve the issue. As a temporary workaround, consider restricting the use of SSL/TLS certificates to minimize the risk of exploitation. Additionally, ensure that all connections to the Device Manager components are properly validated to prevent Man in the Middle Attacks.

Correção

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-03974
CVE-2023-34143

Produtos afetados

Hitachi Device Manager