Fujitsu ETERNUS SF ACM/SC/Express Confidentiality Vulnerability
Vulnerability
A vulnerability exists in Fujitsu/Fsas Technologies ETERNUS SF AdvancedCopy Manager, Storage Cruiser, and Express versions prior to 16.8-16.9.1 PA 2025-12. When maintenance data is accessible by an authority other than the ETERNUS SF Admin, this vulnerability could allow an attacker to impact system confidentiality, integrity, and availability.
Impact
Exploitation of this vulnerability could lead to unauthorized access to maintenance data, potentially allowing for misuse of authorization credentials and impacting system confidentiality, integrity, and availability.
Remediation
Users are advised to update to ETERNUS SF versions 16.8-16.9.1 PA 2025-12 and follow general security best practices. If maintenance data was previously accessible by an authority other than ETERNUS SF Admin, it should be deleted from the management terminal. Additionally, ETERNUS SF administrator passwords should be changed.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
