CVE-2019-5408 describes a vulnerability in Hitachi Command View Advanced Edition (CVAE) products, specifically Device Manager GUI versions 7.0.0-00 to earlier than 8.6.1-02, and associated RepMgr and TSMgr installations. This flaw allows for the exposure of configuration information from hosts and storage systems managed by the Device Manager server. The vulnerability carries a CVSS v3 score of 6.5 (Medium), indicating a network-based attack with low complexity, requiring no user interaction, and resulting in low confidentiality and integrity impacts, but no availability impact. This means an unauthenticated attacker could potentially access and modify sensitive configuration data. There is no evidence of active exploitation, publicly available exploit code in Metasploit, Nuclei, or ExploitDB, and minimal community discussion or media coverage surrounding this CVE. Organizations are advised to upgrade to Device Manager version 8.6.2-02 or later to remediate the issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.0.0-00, < 8.6.1-02CPE matchmatch criteria | cpe:2.3:a:hp:xp7_device_manager:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:hp:xp7_replication_manager:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:hp:xp7_tiered_storage_manager:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.