• Tech News
  • Fintech
  • Startup
  • Games
  • Ar & Vr
  • Reviews
  • How To
  • More
    • Mobile Tech
    • Pc & Laptop
    • Security
What's Hot

Xiaomi Pad 8 Pro review: Classic Xiaomi good value

April 3, 2026

Poco X8 Pro Max review: Minimum spend, maximum speed

April 1, 2026

Sihoo Doro C300 ergonomic office chair review: Affordable ergonomics

April 1, 2026
Facebook Twitter Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook Twitter Instagram Pinterest VKontakte
Behind The ScreenBehind The Screen
  • Tech News
  • Fintech
  • Startup
  • Games
  • Ar & Vr
  • Reviews
  • How To
  • More
    • Mobile Tech
    • Pc & Laptop
    • Security
Behind The ScreenBehind The Screen
Home»Security»Fujitsu Cloud Storage Vulnerabilities Could Expose Backups To Attackers
Security

Fujitsu Cloud Storage Vulnerabilities Could Expose Backups To Attackers

June 28, 2022No Comments2 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Latest Hacking News
Share
Facebook Twitter LinkedIn Pinterest Email

Extreme safety vulnerabilities within the Fujitsu cloud storage system uncovered backups to unauthenticated attackers. Particularly, the bug affected the FUJITSU ETERNUS CS8000 Management Middle, which happily the distributors patched following the bug report. Due to this fact, customers should guarantee updating their units to obtain the patches.

Fujitsu Cloud Storage Vulnerabilities

In accordance with a current post from the NCC Group’s Fox-IT, the crew found two completely different safety vulnerabilities within the Fujitsu cloud storage system.

Particularly, they discovered command injection flaws affecting the Fujitsu ETERNUS CS8000 (Management Middle) whereas inspecting a consumer’s backup techniques. They observed a scarcity of consumer enter validation in two PHP scripts usually out there post-authentication. As acknowledged,

The online-application used to handle the backups was inspected, which lead NCC Group’s Fox-IT to find the existence of two scripts, that are accessible by any consumer on the community and which move consumer enter on to the “shell_exec” and “system” features.

One of many vulnerabilities affected the "grel_finfo" perform in grel.php, permitting an adversary to execute arbitrary instructions. An attacker may obtain the specified outcomes by tweaking the username (“consumer”), password (“pw”), and file-name (“file”) parameters with particular characters.

Whereas the second vulnerability existed within the "requestTempFile" perform in hw_view.php, permitting an adversary to change "unitName" POST parameter through particular characters to execute codes.

Fujitsu Patched The Bugs

After discovering these vulnerabilities, the researchers contacted Fujitsu, which, in response, developed related fixes.

Of their advisory, Fujitsu admitted that the vulnerabilities usually affected older variations. Whereas Fujitsu launched the patches with Fujitsu ETERNUS CS8000 (Management Middle) variations v8.1A SP02 P04 and v8.0A SP01 P03 H035.

See also  Keona Clipper Malware Replaces Crypto Wallet Addresses In Clipboard

So now, customers ought to guarantee updating to the newest variations to obtain the patches for these essential vulnerabilities. Nonetheless, the distributors urge the purchasers to get in contact with buyer help for help in getting these updates.

A devoted buyer request to Fujitsu through ServiceNow or Assist Assistant is required, as a result of software program distribution mannequin.

For now, Fujitsu has confirmed to have discovered no proof of vulnerability exploits within the wild.

Source link

attackers Backups Cloud Expose Fujitsu storage vulnerabilities
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Apple Mulled Entering the Cloud Wars With an AWS Competitor

July 4, 2025

SSD vs. HDD: Which Storage Is Better for Your Business?

January 30, 2025

New Optical Storage Breakthrough Could Revitalize CDs With Ultra-High Density

October 29, 2024

Running Out of Space on Your iPhone, iPad, Mac or PC? This is The Best Way to Get 2TB of Cloud Storage for Lifetime – iDrop News

September 25, 2024
Add A Comment

Comments are closed.

Editors Picks

Visa Plans on Auto Crypto Payments

December 22, 2022

Samsung Galaxy S25 Ultra hands-on: A new look, more AI, but not much else

January 22, 2025

Petting dogs in games is old news: in boomer shooter Ripout, you can pet your gun

August 27, 2022

Versus Evil is publishing post-apocalyptic Australia RPG Broken Roads, now delayed to 2023

August 20, 2022

Subscribe to Updates

Get the latest news and Updates from Behind The Scene about Tech, Startup and more.

Top Post

Xiaomi Pad 8 Pro review: Classic Xiaomi good value

Poco X8 Pro Max review: Minimum spend, maximum speed

Sihoo Doro C300 ergonomic office chair review: Affordable ergonomics

Behind The Screen
Facebook Twitter Instagram Pinterest Vimeo YouTube
  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 behindthescreen.fr - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.