Information disclosure in Storage Protect Server - CVE-2023-40368

 

Information disclosure in Storage Protect Server - CVE-2023-40368

Published: December 20, 2023


Vulnerability identifier: #VU84590
CSH Severity: Low
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-40368
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local privileged user to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application. A local privileged user can gain unauthorized access to sensitive information from the administrative command line client.


Affected software

Storage Protect Server
Storage Protect Client
Storage Protect for Space Management
Storage Protect for Virtual Environments: Data Protection for VMware
Storage Protect for Virtual Environments: Data Protection for Hyper-V

How to mitigate CVE-2023-40368

Install updates from vendor's website.

Storage Protect Server - update to 8.1.20
Storage Protect Client - update to 8.1.20.0
Storage Protect for Space Management - update to 8.1.20.0
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.1.20.0
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.1.20.0

External References

Related Security Bulletins