Description
Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform.

This issue affects Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H: before DKCMAIN Ver. 93-07-26-xx/00, GUM Ver. 93-07-26/00; Hitachi Virtual Storage Platform 5100, 5500, 5100H, 5500H, 5200, 5600, 5200H, 5600H: before DKCMAIN Ver. 90-09-27-00/00, GUM Ver. 90-09-27/00; Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900: before DKCMAIN Ver. 88-08-16-xx/00, GUM Ver. 88-08-20/00.
Published: 2026-06-29
Score: 8.3 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper Authorization Vulnerability of the maintenance utility in Hitachi Virtual Storage Platform allows an attacker who can reach the utility to bypass intended access controls and perform privileged actions on the system. The flaw arises from missing or insufficient authorization checks, enabling unauthorized users to use maintenance functions beyond their permitted scope, potentially accessing or altering data and configuration settings. The weakness is classified as CWE-862, which focuses on missing or ineffective authorization controls.

Affected Systems

The issue affects Hitachi Virtual Storage Platform models E390, E590, E790, E990, E1090, and their "H" variants before DKCMAIN Ver. 93-07-26‑xx/00 and GUM Ver. 93-07-26/00; models 5100, 5500, 5100H, 5500H, 5200, 5600, 5200H, 5600H before DKCMAIN Ver. 90-09-27‑00/00 and GUM Ver. 90-09-27/00; and models G130, G150, G350, G370, G700, G900, F350, F370, F700, F900 before DKCMAIN Ver. 88-08-16‑xx/00 and GUM Ver. 88-08-20/00.

Risk and Exploitability

The CVSS score of 8.3 indicates a high-severity vulnerability, and the EPSS score is not available, meaning an exact exploitation probability cannot be quantified from the data. The vulnerability is not listed in the CISA KEV catalog. Because the maintenance utility is typically accessed over the platform’s management network, the likely attack vector is remote, although local attackers with network access could also exploit the flaw. Exploitation would require the attacker to reach the maintenance interface, bypass authentication checks, and trigger privileged functions, which could compromise data integrity and confidentiality.

Generated by OpenCVE AI on June 29, 2026 at 08:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade all affected Hitachi Virtual Storage Platform systems to the fixed firmware versions: ensure DKCMAIN is at least Ver. 93‑07‑26‑xx/00 and GUM at least Ver. 93‑07‑26/00 for E-series, DKCMAIN at least Ver. 90‑09‑27‑00/00 and GUM at least Ver. 90‑09‑27/00 for 500/600 series, and DKCMAIN at least Ver. 88‑08‑16‑xx/00 and GUM at least Ver. 88‑08‑20/00 for G/F series
  • Restrict network access to the maintenance utility by implementing role‑based access controls and firewall filtering so that only authorized management hosts can reach the interface
  • Monitor audit logs for abnormal or repeated access attempts to the maintenance utility and investigate any unauthorized activity promptly

Generated by OpenCVE AI on June 29, 2026 at 08:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 29 Jun 2026 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Hitachi
Hitachi 5100
Hitachi 5100h
Hitachi 5200
Hitachi 5200h
Hitachi 5500
Hitachi 5500h
Hitachi 5600
Hitachi 5600h
Hitachi e1090
Hitachi e1090h
Hitachi e390
Hitachi e390h
Hitachi e590
Hitachi e590h
Hitachi e790
Hitachi e790h
Hitachi e990
Hitachi f350
Hitachi f370
Hitachi f700
Hitachi f900
Hitachi g130
Hitachi g150
Hitachi g350
Hitachi g370
Hitachi g700
Hitachi g900
Vendors & Products Hitachi
Hitachi 5100
Hitachi 5100h
Hitachi 5200
Hitachi 5200h
Hitachi 5500
Hitachi 5500h
Hitachi 5600
Hitachi 5600h
Hitachi e1090
Hitachi e1090h
Hitachi e390
Hitachi e390h
Hitachi e590
Hitachi e590h
Hitachi e790
Hitachi e790h
Hitachi e990
Hitachi f350
Hitachi f370
Hitachi f700
Hitachi f900
Hitachi g130
Hitachi g150
Hitachi g350
Hitachi g370
Hitachi g700
Hitachi g900

Mon, 29 Jun 2026 07:00:00 +0000

Type Values Removed Values Added
Description Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform. This issue affects Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H: before DKCMAIN Ver. 93-07-26-xx/00, GUM Ver. 93-07-26/00; Hitachi Virtual Storage Platform 5100, 5500, 5100H, 5500H, 5200, 5600, 5200H, 5600H: before DKCMAIN Ver. 90-09-27-00/00, GUM Ver. 90-09-27/00; Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900: before DKCMAIN Ver. 88-08-16-xx/00, GUM Ver. 88-08-20/00.
Title Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Hitachi

Published:

Updated: 2026-06-29T05:52:39.570Z

Reserved: 2025-03-28T06:25:15.368Z

Link: CVE-2025-2902

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-29T11:00:05Z

Weaknesses