Lucene search

K
cve[email protected]CVE-2022-41553
HistoryNov 01, 2022 - 3:15 a.m.

CVE-2022-41553

2022-11-0103:15:10
CWE-532
web.nvd.nist.gov
31
7
cve
2022
41553
insertion
sensitive information
temporary file
vulnerability
hitachi
infrastructure analytics advisor
ops center analyzer
linux
local users
gain

6.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

5.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Insertion of Sensitive Information into Temporary File vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Analytics probe component), Hitachi Ops Center Analyzer on Linux (Hitachi Ops Center Analyzer probe component) allows local users to gain sensitive information.
This issue affects Hitachi Infrastructure Analytics Advisor: from 2.0.0-00 through 4.4.0-00; Hitachi Ops Center Analyzer: from 10.0.0-00 before 10.9.0-00.

Affected configurations

NVD
Node
hitachiinfrastructure_analytics_advisorRange2.0.0-004.4.0-00
AND
linuxlinux_kernelMatch-x64
Node
hitachiops_center_analyzerRange10.0.0-0010.9.0-00
AND
linuxlinux_kernelMatch-x64

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "modules": [
      "Analytics probe"
    ],
    "platforms": [
      "Linux"
    ],
    "product": "Hitachi Infrastructure Analytics Advisor",
    "vendor": "Hitachi",
    "versions": [
      {
        "lessThanOrEqual": "4.4.0-00",
        "status": "affected",
        "version": "2.0.0-00",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "modules": [
      "Hitachi Ops Center Analyzer probe"
    ],
    "platforms": [
      "Linux"
    ],
    "product": "Hitachi Ops Center Analyzer",
    "vendor": "Hitachi",
    "versions": [
      {
        "changes": [
          {
            "at": "10.9.0-00",
            "status": "unaffected"
          }
        ],
        "lessThan": "10.9.0-00",
        "status": "affected",
        "version": "10.0.0-00",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

6.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

5.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Related for CVE-2022-41553