Junglewise Threat Intelligence

CVE-2025-0824: Hitachi Virtual Storage Platform One Block firmware update validation failure

CVE-2025-0824 · Severity: low · CVSS 3.7 · Published 2026-06-29

Vendors: Hitachi.

Executive brief

Hitachi Virtual Storage Platform One Block systems, which are high-performance data storage solutions for enterprise environments, contain a vulnerability in their firmware update process. An attacker could potentially bypass security checks to install unauthorized firmware, which could lead to system instability or a partial loss of service. While the risk is rated as low due to the complexity of the attack and the requirement for user interaction, a successful exploit could compromise the integrity of the storage hardware.

Technical details

A vulnerability classified as Improper Verification of Cryptographic Signature (CWE-347) exists in the firmware replacement function of Hitachi Virtual Storage Platform One Block (models 23, 24, 26, and 28). The root cause is a lack of proper validation for firmware updates, specifically within the DKCMAIN and ESM components. An attacker with low-level privileges and network access could potentially exploit this during a firmware update process, though the attack requires high complexity and user interaction. Successful exploitation could allow an attacker to impact the integrity and availability of the storage system by deploying unauthorized microcode. Hitachi has released updated microcode versions (DKCMAIN A3-04-21-40/00 and ESM A3-04-21/00) to remediate this issue.

Affected products

  • Hitachi Virtual Storage Platform One Block 23 before DKCMAIN A3-04-21-40/00, ESM A3-04-21/00
  • Hitachi Virtual Storage Platform One Block 24 before DKCMAIN A3-04-21-40/00, ESM A3-04-21/00
  • Hitachi Virtual Storage Platform One Block 26 before DKCMAIN A3-04-21-40/00, ESM A3-04-21/00
  • Hitachi Virtual Storage Platform One Block 28 before DKCMAIN A3-04-21-40/00, ESM A3-04-21/00

Timeline

  • 2026-03-27: advisory: Initial security information published by Hitachi
  • 2026-06-29: disclosed: CVE published to NVD dataset

References

Related threats