CVE-2020-36695
Last modified
CVE-2020-36695 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Incorrect Default Permissions vulnerability in Hitachi Device Manager on Linux (Device Manager Server component), Hitachi Tiered Storage Manager on Linux, Hitachi Replication Manager on Linux, Hitachi Tuning Manager on Linux (Hitachi Tuning Manager server, Hitachi Tuning Manager - Agent for RAID, Hitachi Tuning Manager - Agent for NAS components), Hitachi Compute Systems Manager on Linux allows File Manipulation.This issue affects Hitachi Device Manager: before 8.8.5-02; Hitachi Tiered Storage Manager: before 8.8.5-02; Hitachi Replication Manager: before 8.8.5-02; Hitachi Tuning Manager: before 8.8.5-02; Hitachi Compute Systems Manager: before 8.8.3-08. . EPSS estimates a 0.15% chance of exploitation in the next 30 days.
Description
Incorrect Default Permissions vulnerability in Hitachi Device Manager on Linux (Device Manager Server component), Hitachi Tiered Storage Manager on Linux, Hitachi Replication Manager on Linux, Hitachi Tuning Manager on Linux (Hitachi Tuning Manager server, Hitachi Tuning Manager - Agent for RAID, Hitachi Tuning Manager - Agent for NAS components), Hitachi Compute Systems Manager on Linux allows File Manipulation.This issue affects Hitachi Device Manager: before 8.8.5-02; Hitachi Tiered Storage Manager: before 8.8.5-02; Hitachi Replication Manager: before 8.8.5-02; Hitachi Tuning Manager: before 8.8.5-02; Hitachi Compute Systems Manager: before 8.8.3-08.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hitachi | Compute Systems Manager | < 8.8.3-08 |
| Hitachi | Device Manager | < 8.8.5-02 |
| Hitachi | Replication Manager | < 8.8.5-02 |
| Hitachi | Tiered Storage Manager | < 8.8.5-02 |
| Hitachi | Tuning Manager | < 8.8.5-02 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-36695?
How severe is CVE-2020-36695?
How do I fix CVE-2020-36695?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-36670The NEX-Forms. plugin for WordPress is vulnerable to unautho…6.3
- CVE-2020-3668u'Buffer overflow while parsing PMF enabled MCBC frames due …9.8
- CVE-2020-3669u'Buffer Overflow issue in WLAN tcp ip verification due to u…9.8
- CVE-2020-36691An issue was discovered in the Linux kernel before 5.8. lib/…5.5
- CVE-2020-36692A reflected XSS via POST vulnerability in report scheduler o…5.4
- CVE-2020-36694An issue was discovered in netfilter in the Linux kernel bef…6.7
- CVE-2020-36696The Product Input Fields for WooCommerce plugin for WordPres…7.5
- CVE-2020-36697The WP GDPR plugin for WordPress is vulnerable to authorizat…6.5
- CVE-2020-36698The Security & Malware scan by CleanTalk plugin for WordPres…8.8
- CVE-2020-36699The Quick Page/Post Redirect Plugin for WordPress is vulnera…4.3
- CVE-2020-3670u'Potential out of bounds read while processing downlink NAS…9.1
- CVE-2020-36700The Page Builder: KingComposer plugin for WordPress is vulne…8.8
Are you affected by CVE-2020-36695?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
