Learn about CVE-2020-36695, an Incorrect Default Permissions vulnerability in Hitachi products on Linux, allowing File Manipulation. Discover impacts, affected systems, and mitigation steps.
This CVE-2020-36695 article provides insights into a File and Directory Permission Vulnerability in Hitachi Command Suite.
Understanding CVE-2020-36695
What is CVE-2020-36695?
The CVE-2020-36695 vulnerability involves an Incorrect Default Permissions issue in various Hitachi products on Linux, allowing File Manipulation.
The Impact of CVE-2020-36695
The vulnerability has a base score of 6.6, indicating a medium severity level. It can lead to high availability impact due to file manipulation.
Technical Details of CVE-2020-36695
Vulnerability Description
The vulnerability arises from Incorrect Default Permissions in Hitachi Device Manager, Tiered Storage Manager, Replication Manager, Tuning Manager, and Compute Systems Manager on Linux.
Affected Systems and Versions
Exploitation Mechanism
The vulnerability allows attackers to manipulate files due to incorrect default permissions, potentially leading to unauthorized access and data compromise.
Mitigation and Prevention
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates
Ensure that all Hitachi products mentioned are updated to versions 8.8.5-02 or higher to mitigate the vulnerability.