[Japanese] | |
JVNDB-2024-000068 | |
JP1/Extensible SNMP Agent fails to restrict access permissions | |
Overview | |
JP1/Extensible SNMP Agent provided by Hitachi fails to restrict access permissions (CWE-276). | |
CVSS Severity (What is CVSS?) | |
CVSS V3 Severity:
Base Metrics 3.3 (Low) [IPA Score]
Assuming an attack scenario in which a logged-in attacker with some non-administrative privilege puts a crafted file in a specific directory, "Integrity (I)" is treated as the primary impact, whereas "Confidentiality (C)" and "Availability (A)" are treated as secondary.
| |
Affected Products | |
| |
Hitachi, Ltd | |
| |
Impact | |
If an authenticated attacker who can log in to the product places a specially crafted DLL file in a specific directory, arbitrary code may be executed with the administrative privilege. | |
Solution | |
[Update the Software] | |
Vendor Information | |
Hitachi, Ltd | |
CWE (What is CWE?) | |
| |
CVE (What is CVE?) | |
| |
References | |
| |
Revision History | |
|
Date Public | 2024/07/03 |
Date First Published | 2024/07/03 |
Date Last Updated | 2024/07/03 |