Description
Improper restriction of excessive authentication attempts vulnerability in Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, Hitachi Virtual Storage Platform One Block 23, One Block 24, One Block 26, One Block 28.

This issue affects Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, Hitachi Virtual Storage Platform One Block 23, One Block 24, One Block 26, One Block 28  : before DKCMAIN Ver 88-08-16-xx/00, GUM Ver. 88-08-20/00, before DKCMAIN Ver 93-07-26-xx/00, GUM Ver. 93-07-26/00, before DKCMAIN Ver A3-04-02-xx/00, EMS Ver. A3-04-02/00, before DKCMAIN Ver A3-03-41-xx/00, EMS Ver. A3-03-41/00, before DKCMAIN Ver A3-03-03-xx/00, EMS Ver. A3-03-02/00.
Published: 2026-05-07
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from the lack of a mechanism to limit consecutive failed authentication attempts on the Hitachi Virtual Storage Platform. Attackers can repeatedly attempt to guess credentials without encountering account lockout or throttling, after which they can gain access to the administrative interface. The flaw falls under CWE‑307 (Improper Restriction of Excessive Authentication Attempts) and could lead to unauthorized control over the storage system, including configuration changes, data exfiltration, or service disruption.

Affected Systems

Affected variants include the Hitachi Virtual Storage Platform lines G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, as well as E390, E590, E790, E990, E1090 and their enhanced H‑series counterparts, and the One Block series (23, 24, 26, 28). The vulnerability applies to firmware versions prior to DKCMAIN Ver 88‑08‑16‑xx/00, GUM Ver 88‑08‑20/00, DKCMAIN Ver 93‑07‑26‑xx/00, GUM Ver 93‑07‑26/00, DKCMAIN Ver A3‑04‑02‑xx/00, EMS Ver A3‑04‑02/00, DKCMAIN Ver A3‑03‑41‑xx/00, EMS Ver A3‑03‑41/00, DKCMAIN Ver A3‑03‑03‑xx/00, and EMS Ver A3‑03‑02/00. Current releases after these build numbers contain the fix.

Risk and Exploitability

The CVSS base score of 5.3 indicates a moderate impact. EPSS is not available, so the current estimated likelihood of exploitation is unknown, but the lack of an account lockout mechanism suggests a high potential for brute‑force attacks if the management interface is exposed. The vulnerability is not listed in the CISA KEV catalog, so no known active exploitation has been reported, but the presence of an unauthenticated attack path warrants timely patching. Attackers would first need network access to the management plane, and could then repeatedly submit login requests until credentials are discovered.

Generated by OpenCVE AI on May 7, 2026 at 09:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the storage platform firmware to a version that includes the fix (post the listed release numbers).
  • Implement centralized authentication and enforce lockout policies or rate limiting on the management interface.
  • Restrict management network access to known administrative IP ranges and monitor authentication logs for repeated failures.

Generated by OpenCVE AI on May 7, 2026 at 09:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 07 May 2026 08:30:00 +0000

Type Values Removed Values Added
Description Improper restriction of excessive authentication attempts vulnerability in Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, Hitachi Virtual Storage Platform One Block 23, One Block 24, One Block 26, One Block 28. This issue affects Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, Hitachi Virtual Storage Platform One Block 23, One Block 24, One Block 26, One Block 28  : before DKCMAIN Ver 88-08-16-xx/00, GUM Ver. 88-08-20/00, before DKCMAIN Ver 93-07-26-xx/00, GUM Ver. 93-07-26/00, before DKCMAIN Ver A3-04-02-xx/00, EMS Ver. A3-04-02/00, before DKCMAIN Ver A3-03-41-xx/00, EMS Ver. A3-03-41/00, before DKCMAIN Ver A3-03-03-xx/00, EMS Ver. A3-03-02/00.
Title Improper Restriction of Excessive Authentication Attempts vulnerability in Hitachi Virtual Storage Platform
Weaknesses CWE-307
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Hitachi

Published:

Updated: 2026-05-07T13:41:12.214Z

Reserved: 2025-03-19T01:13:12.468Z

Link: CVE-2025-2514

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-07T09:16:26.183

Modified: 2026-05-07T09:16:26.183

Link: CVE-2025-2514

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-07T09:30:06Z

Weaknesses