« Volver al listado

CVE-2022-34883

Estado: ModificadaAlta (8.8)—

OS Command Injection vulnerability in Hitachi RAID Manager Storage Replication Adapter allows remote authenticated users to execute arbitrary OS commands. This issue affects: Hitachi RAID Manager Storage Replication Adapter 02.01.04 versions prior to 02.03.02 on Windows; 02.05.00 versions prior to 02.05.01 on Windows and Docker.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-34883",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "hirt@hitachi.co.jp",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.2,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.2
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "hirt@hitachi.co.jp",
      "affectedData": [
        {
          "vendor": "Hitachi",
          "product": "RAID Manager Storage Replication Adapter",
          "versions": [
            {
              "status": "affected",
              "changes": [
                {
                  "at": "02.03.02",
                  "status": "unaffected"
                }
              ],
              "version": "02.01.04",
              "lessThan": "02.03.02",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "Windows"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Hitachi",
          "product": "RAID Manager Storage Replication Adapter",
          "versions": [
            {
              "status": "affected",
              "changes": [
                {
                  "at": "02.05.01",
                  "status": "unaffected"
                }
              ],
              "version": "02.05.00",
              "lessThan": "02.05.01",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "Windows",
            "Docker"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2022-09-06T07:15:07.420",
  "references": [
    {
      "url": "https://www.hitachi.com/products/it/storage-solutions/sec_info/2022/2022_307.html",
      "source": "hirt@hitachi.co.jp"
    },
    {
      "url": "https://www.hitachi.com/products/it/storage-solutions/sec_info/2022/2022_307.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "hirt@hitachi.co.jp",
      "description": [
        {
          "lang": "en",
          "value": "CWE-78"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-78"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "OS Command Injection vulnerability in Hitachi RAID Manager Storage Replication Adapter allows remote authenticated users to execute arbitrary OS commands. This issue affects: Hitachi RAID Manager Storage Replication Adapter 02.01.04 versions prior to 02.03.02 on Windows; 02.05.00 versions prior to 02.05.01 on Windows and Docker."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de inyección de comandos del Sistema Operativo en Hitachi RAID Manager Storage Replication Adapter permite a usuarios remotos autenticados ejecutar comandos arbitrarios del Sistema Operativo. Este problema afecta a: Hitachi RAID Manager Storage Replication Adapter 02.01.04 versiones anteriores a 02.03.02 en Windows; 02.05.00 versiones anteriores a 02.05.01 en Windows y Docker.\n"
    }
  ],
  "lastModified": "2026-06-17T04:51:05.813",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:hitachi:raid_manager_storage_replication_adapter:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D3D76EA4-5A07-43D5-A315-3E2AA5DEE7E3",
              "versionEndExcluding": "02.03.02",
              "versionStartIncluding": "02.01.04"
            },
            {
              "criteria": "cpe:2.3:a:hitachi:raid_manager_storage_replication_adapter:02.05.00:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0DCED4B2-6C7F-4DE0-BD91-67D9EA50FFB1"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:hitachi:raid_manager_storage_replication_adapter:02.05.00:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0DCED4B2-6C7F-4DE0-BD91-67D9EA50FFB1"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:docker:docker:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "231A8A55-A319-4878-91DA-4FD91CF0549E"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "hirt@hitachi.co.jp"
}