Unintended Information Disclosure in SMU Versions Prior to 14.8.7825.01

Unintended Information Disclosure in SMU Versions Prior to 14.8.7825.01

CVE-2023-5808 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in a Storage administrative role are able to access HNAS configuration backup and diagnostic data, that would normally be barred to that specific administrative role.

Learn more about our User Device Pen Test.