CVE-2022-34883

High
|8.8
No Exploit

Plain English Summary

AI-powered analysis for quick understanding

This vulnerability allows an attacker with valid login credentials to remotely run any command on the affected Hitachi RAID Manager Storage Replication Adapter, potentially giving them full control over the system. It affects specific versions of the software on Windows and Docker, so users need to ensure they are using the latest updates to protect against this risk.

Technical Description

OS Command Injection vulnerability in Hitachi RAID Manager Storage Replication Adapter allows remote authenticated users to execute arbitrary OS commands. This issue affects: Hitachi RAID Manager Storage Replication Adapter 02.01.04 versions prior to 02.03.02 on Windows; 02.05.00 versions prior to 02.05.01 on Windows and Docker.

CVSS Vector Analysis

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
Confidentiality ImpactHigh
Integrity ImpactHigh
Availability ImpactHigh
ScopeUnchanged

Vector String

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References