9.8

CVE-2026-71377

Command Argument Injection Vulnerability in Cosminexus Component Container

Command Argument Injection Vulnerability in Cosminexus Component Container.

This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through 11-10-11, from 11-00 through 11-00-12, from 09-87 before 09-87-10, from 09-80 through 09-80-04, from 09-70 before 09-70-28, from 09-50 through 09-50-22, and from 09-00 through 09-00-18.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerHitachi
≫
Produkt Cosminexus Component Container
Default Statusunaffected
Version 11-70-01
Version < 11-70-03
Status affected
Version 11-60
Version < 11-60-03
Status affected
Version <= 11-50-03
Version 11-50
Status affected
Version <= 11-40-03
Version 11-40
Status affected
Version <= 11-30-08
Version 11-30
Status affected
Version 11-20
Version < 11-20-10
Status affected
Version <= 11-10-11
Version 11-10
Status affected
Version <= 11-00-12
Version 11-00
Status affected
Version 09-87
Version < 09-87-10
Status affected
Version <= 09-80-04
Version 09-80
Status affected
Version 09-70
Version < 09-70-28
Status affected
Version <= 09-50-22
Version 09-50
Status affected
Version <= 09-00-18
Version 09-00
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.31% 0.239
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
hirt@hitachi.co.jp 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.

https://www.hitachi.com/products/it/software/security/info/vuls/hitachi-sec-2026-133/index.html