4.4

CVE-2020-36605

File Permissions Vulnerability in Hitachi Infrastructure Analytics Advisor, Hitachi Ops Center Analyzer, Hitachi Ops Center Viewpoint

Incorrect Default Permissions vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Analytics probe component), Hitachi Ops Center Analyzer on Linux (Analyzer probe component), Hitachi Ops Center Viewpoint on Linux (Viewpoint RAID Agent component) allows local users to read and write specific files.



This issue affects Hitachi Infrastructure Analytics Advisor: from 2.0.0-00 through 4.4.0-00; Hitachi Ops Center Analyzer: from 10.0.0-00 before 10.9.0-00; Hitachi Ops Center Viewpoint: from 10.8.0-00 before 10.9.0-00.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hitachi ≫ Infrastructure Analytics Advisor Version >= 2.0.0-00 <= 4.4.0-00
   Linux ≫ Linux Kernel Version - HwPlatform x64
   Microsoft ≫ Windows Version - HwPlatform x64
Hitachi ≫ Ops Center Analyzer Version >= 10.0.0-00 < 10.9.0-00
   Linux ≫ Linux Kernel Version - HwPlatform x64
Hitachi ≫ Ops Center Viewpoint Version >= 10.8.0-00 < 10.9.0-00
   Linux ≫ Linux Kernel Version - HwPlatform x64
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.15% 0.049
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.4 1.8 2.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
hirt@hitachi.co.jp 6.6 1.8 4.7
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
CWE-276 Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.

https://www.hitachi.com/products/it/software/security/info/vuls/hitachi-sec-2022-134/index.html
Vendor Advisory