Remote Code Execution Vulnerability in Hitachi Storage Navigator
CVE-2025-1978

8.3HIGH

What is CVE-2025-1978?

A Remote Code Execution vulnerability exists in the Hitachi Storage Navigator and maintenance console of various Hitachi Virtual Storage Platform models. This vulnerability can potentially allow an attacker to execute arbitrary code, which could lead to unauthorized access to sensitive data or system disruption. It affects multiple versions, specifically those prior to DKCMAIN Ver. 88-08-16-xx/00 and SVP Ver. 88-08-18-xx/00, among others. Organizations utilizing the affected products are strongly encouraged to implement appropriate security measures to mitigate the risk.

Affected Version(s)

Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H 0

Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H 0

Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H 0

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thomas Josef Riedmaier, Siemens Energy.
.