Rewterz Threat Advisory – Multiple Citrix ADC and Gateway Vulnerabilities
July 19, 2023Rewterz Threat Advisory – ICS: Rockwell Automation Kinetix Vulnerability
July 19, 2023Rewterz Threat Advisory – Multiple Citrix ADC and Gateway Vulnerabilities
July 19, 2023Rewterz Threat Advisory – ICS: Rockwell Automation Kinetix Vulnerability
July 19, 2023Severity
High
Analysis Summary
CVE-2023-34142 CVSS:9
Hitachi Device Manager for Windows and Hitachi Device Manager for Linux could allow a remote attacker to obtain sensitive information, caused by cleartext transmission of sensitive information. An attacker could exploit this vulnerability to obtain sensitive information and use this information to launch further attacks against the affected system.
CVE-2023-34143 CVSS:5.6
Hitachi Device Manager for Windows and Hitachi Device Manager for Linux are vulnerable to a man-in-the-middle attack, caused by improper validation of certificates with host mismatch in the Device Manager Server, Device Manager Agent, Host Data Collector components. A remote attacker could exploit this vulnerability to launch a man-in-the-middle attack and gain access to the communication channel between endpoints to obtain sensitive information or further compromise the system.
Impact
- Information Disclosure
- Unauthorized Access
Indicators Of Compromise
CVE
- CVE-2023-34142
- CVE-2023-34143
Affected Vendors
Hitachi
Affected Products
- Hitachi Device Manager for Windows 8.8.5-01
- Hitachi Device Manager for Linux 8.8.5-01