6.6

CVE-2020-36605

Incorrect Default Permissions vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Analytics probe component), Hitachi Ops Center Analyzer on Linux (Analyzer probe component), Hitachi Ops Center Viewpoint on Linux (Viewpoint RAID Agent component) allows local users to read and write specific files.



This issue affects Hitachi Infrastructure Analytics Advisor: from 2.0.0-00 through 4.4.0-00; Hitachi Ops Center Analyzer: from 10.0.0-00 before 10.9.0-00; Hitachi Ops Center Viewpoint: from 10.8.0-00 before 10.9.0-00.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HitachiInfrastructure Analytics Advisor Version >= 2.0.0-00 <= 4.4.0-00
   LinuxLinux Kernel Version- HwPlatformx64
   MicrosoftWindows Version- HwPlatformx64
HitachiOps Center Analyzer Version >= 10.0.0-00 < 10.9.0-00
   LinuxLinux Kernel Version- HwPlatformx64
HitachiOps Center Viewpoint Version >= 10.8.0-00 < 10.9.0-00
   LinuxLinux Kernel Version- HwPlatformx64
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.04% 0.116
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.4 1.8 2.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
hirt@hitachi.co.jp 6.6 1.8 4.7
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
CWE-276 Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.