Fujitsu ETERNUS SF ACM/SC/Express Confidentiality Vulnerability

Vulnerability

A vulnerability exists in Fujitsu/Fsas Technologies ETERNUS SF AdvancedCopy Manager, Storage Cruiser, and Express versions prior to 16.8-16.9.1 PA 2025-12. When maintenance data is accessible by an authority other than the ETERNUS SF Admin, this vulnerability could allow an attacker to impact system confidentiality, integrity, and availability.

Impact

Exploitation of this vulnerability could lead to unauthorized access to maintenance data, potentially allowing for misuse of authorization credentials and impacting system confidentiality, integrity, and availability.

Remediation

Users are advised to update to ETERNUS SF versions 16.8-16.9.1 PA 2025-12 and follow general security best practices. If maintenance data was previously accessible by an authority other than ETERNUS SF Admin, it should be deleted from the management terminal. Additionally, ETERNUS SF administrator passwords should be changed.

Added: Dec 24, 2025, 9:24 PM
Updated: Dec 24, 2025, 9:24 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.9
exploitability
5.2
remediation
0.0
relevance
1.6
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.