CVE-2023-6814 is a sensitive information disclosure vulnerability (CWE-532) in Hitachi Cosminexus Component Container versions 11-30 (before 11-30-05), 11-20 (before 11-20-07), 11-10 (before 11-10-10), 11-00 (before 11-00-12), and all versions of V8 and V9. This vulnerability allows local users to gain sensitive information due to the insertion of such data into log files. Rated with a CVSS score of 5.6 (Medium), the attack vector is local with high attack complexity, requiring low privileges, and resulting in high confidentiality impact without affecting integrity or availability. There is currently no evidence of active exploitation, nor are there known public exploits available in Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 11-00, < 11-00-12CPE match | cpe:2.3:a:hitachi:cosminexus_component_container:*:*:*:*:*:*:*:* | ||
>= 11-10, < 11-10-10CPE match | cpe:2.3:a:hitachi:cosminexus_component_container:*:*:*:*:*:*:*:* | ||
>= 11-20, < 11-20-07CPE match | cpe:2.3:a:hitachi:cosminexus_component_container:*:*:*:*:*:*:*:* | ||
>= 11-30, < 11-30-05CPE match | cpe:2.3:a:hitachi:cosminexus_component_container:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.