Impact
An observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose sensitive information across the network. The vendor identified this flaw as CWE‑204, a weakness that enables unintended information disclosure. As a result, confidential data that should be protected by the system could be exposed to an attacker, potentially leading to compromised customer data and breach of compliance requirements.
Affected Systems
Microsoft Azure Stack HCI devices are affected by this vulnerability. No specific version information was provided, so all current and future deployments of Azure Stack HCI should be considered at risk until a patch is distributed.
Risk and Exploitability
The CVSS score of 8.6 classifies this flaw as high severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, network‑based access to the HCI cluster; authentication is not required. Once an attacker can reach the vulnerable interface, they can leverage the response difference to retrieve information that should remain confidential.
OpenCVE Enrichment