9.8

CVE-2025-1978

Remote Code Execution Vulnerability in Hitachi Storage Navigator and the maintenance console

Remote Code Execution Vulnerability in Hitachi Storage Navigator and the maintenance console in Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, Hitachi Virtual Storage Platform One Block 23, One Block 24, One Block 26, One Block 28.

This issue affects Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, Hitachi Virtual Storage Platform One Block 23, One Block 24, One Block 26, One Block 28  : before DKCMAIN Ver. 88-08-16-xx/00, SVP Ver. 88-08-18-xx/00, before DKCMAIN Ver. 93-07-26-xx/00, SVP Ver. 93-07-26-xx/00, before DKCMAIN Ver. A3-04-02-xx/00, MPC Ver. A3-04-02-xx/00, before DKCMAIN Ver. A3-03-41-xx/00, MPC Ver. A3-03-41-xx/00, before DKCMAIN Ver. A3-03-03-xx/00, MPC Ver. A3-03-03-xx/00.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HitachiVsp G130 Firmware Version-
   HitachiVsp G130 Version-
HitachiVsp G150 Firmware Version-
   HitachiVsp G150 Version-
HitachiVsp G350 Firmware Version-
   HitachiVsp G350 Version-
HitachiVsp G370 Firmware Version-
   HitachiVsp G370 Version-
HitachiVsp G700 Firmware Version-
   HitachiVsp G700 Version-
HitachiVsp G900 Firmware Version-
   HitachiVsp G900 Version-
HitachiVsp F350 Firmware Version-
   HitachiVsp F350 Version-
HitachiVsp F370 Firmware Version-
   HitachiVsp F370 Version-
HitachiVsp F700 Firmware Version-
   HitachiVsp F700 Version-
HitachiVsp F900 Firmware Version-
   HitachiVsp F900 Version-
HitachiVsp E390 Firmware Version-
   HitachiVsp E390 Version-
HitachiVsp E590 Firmware Version-
   HitachiVsp E590 Version-
HitachiVsp E790 Firmware Version-
   HitachiVsp E790 Version-
HitachiVsp E990 Firmware Version-
   HitachiVsp E990 Version-
HitachiVsp E1090 Firmware Version-
   HitachiVsp E1090 Version-
HitachiVsp E390h Firmware Version-
   HitachiVsp E390h Version-
HitachiVsp E590h Firmware Version-
   HitachiVsp E590h Version-
HitachiVsp E790h Firmware Version-
   HitachiVsp E790h Version-
HitachiVsp E1090h Firmware Version-
   HitachiVsp E1090h Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.32% 0.549
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
hirt@hitachi.co.jp 8.3 3.9 3.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.