Record summary

CVE-2023-6538 has a selected CVSS score of 7.6 (high); EIP currently links 1 catalogued exploit and 1 repository PoC.

Description

SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in Storage, Server or combined Server+Storage administrative roles are able to access SMU configuration backup, that would normally be barred to those specific administrative roles.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List6.0 to < 14.8.7825.01affected

Proofs of concept

2

Catalogued exploits

ExploitDBHNAS SMU 14.8.7825 - Information DisclosureExploitDB exploitby Arslan MasoodNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubArszilla/CVE-2023-6538Repository PoCby ArszillaStars: 1Not analyzed4 files

119.8 KiB

GitHub

PoC details

References

3