Executive brief
A critical security vulnerability has been identified in the management software for Hitachi Virtual Storage Platforms, which are high-performance systems used for enterprise data storage. This flaw allows an unauthorized person to remotely execute commands on the storage management console. If exploited, an attacker could potentially disrupt storage operations, gain unauthorized access to management functions, or compromise the integrity of the storage environment.
Technical details
A remote code execution (RCE) vulnerability exists in Hitachi Storage Navigator and the associated maintenance consoles (SVP/MPC) across multiple Virtual Storage Platform (VSP) models. The vulnerability is classified as Improper Control of Generation of Code (CWE-94), suggesting a code injection flaw within the management interface. An unauthenticated attacker can exploit this over the network to execute arbitrary code on the management processor. This could lead to full compromise of the storage management layer. Hitachi has released microcode updates for affected DKCMAIN, SVP, and MPC components to remediate the issue.
Affected products
- Hitachi Virtual Storage Platform G130/G150/G350/G370/G700/G900 DKCMAIN before 88-08-16-xx/00, SVP before 88-08-18-xx/00
- Hitachi Virtual Storage Platform F350/F370/F700/F900 DKCMAIN before 88-08-16-xx/00, SVP before 88-08-18-xx/00
- Hitachi Virtual Storage Platform E390/E590/E790/E990/E1090/E390H/E590H/E790H/E1090H DKCMAIN before 93-07-26-xx/00, SVP before 93-07-26-xx/00
- Hitachi Virtual Storage Platform One Block 23/24/26/28 DKCMAIN before A3-04-02-xx/00, MPC before A3-04-02-xx/00
Timeline
- 2026-03-27: disclosed: Initial vendor advisory published by Hitachi
- 2026-05-07: advisory: CVE published to NVD