Executive brief
Hitachi Virtual Storage Platforms are high-performance data storage systems used by enterprises to manage and protect large volumes of business-critical information. A security flaw in these systems fails to limit the number of login attempts, which could allow an unauthorized person to repeatedly guess passwords. If successful, this could lead to unauthorized access to the storage management interface and potential exposure of system configuration data.
Technical details
A vulnerability classified as CWE-307 (Improper Restriction of Excessive Authentication Attempts) exists in multiple Hitachi Virtual Storage Platform (VSP) models. The management interfaces (GUM/EMS) do not sufficiently throttle or block repeated failed login attempts. An unauthenticated attacker with network access to the management interface can perform brute-force or dictionary attacks to guess valid credentials. Successful exploitation could lead to unauthorized access to the storage system's management functions and information disclosure. Hitachi has released microcode updates (DKCMAIN) to address this issue across the affected G, F, E, and One Block series.
Affected products
- Hitachi Virtual Storage Platform G130 before DKCMAIN 88-08-16-xx/00, GUM 88-08-20/00
- Hitachi Virtual Storage Platform G150 before DKCMAIN 88-08-16-xx/00, GUM 88-08-20/00
- Hitachi Virtual Storage Platform G350 before DKCMAIN 88-08-16-xx/00, GUM 88-08-20/00
- Hitachi Virtual Storage Platform G370 before DKCMAIN 88-08-16-xx/00, GUM 88-08-20/00
- Hitachi Virtual Storage Platform G700 before DKCMAIN 88-08-16-xx/00, GUM 88-08-20/00
- Hitachi Virtual Storage Platform G900 before DKCMAIN 88-08-16-xx/00, GUM 88-08-20/00
- Hitachi Virtual Storage Platform F350 before DKCMAIN 88-08-16-xx/00, GUM 88-08-20/00
- Hitachi Virtual Storage Platform F370 before DKCMAIN 88-08-16-xx/00, GUM 88-08-20/00
- Hitachi Virtual Storage Platform F700 before DKCMAIN 88-08-16-xx/00, GUM 88-08-20/00
- Hitachi Virtual Storage Platform F900 before DKCMAIN 88-08-16-xx/00, GUM 88-08-20/00
- Hitachi Virtual Storage Platform E390 before DKCMAIN 93-07-26-xx/00, GUM 93-07-26/00
- Hitachi Virtual Storage Platform E590 before DKCMAIN 93-07-26-xx/00, GUM 93-07-26/00
- Hitachi Virtual Storage Platform E790 before DKCMAIN 93-07-26-xx/00, GUM 93-07-26/00
- Hitachi Virtual Storage Platform E990 before DKCMAIN 93-07-26-xx/00, GUM 93-07-26/00
- Hitachi Virtual Storage Platform E1090 before DKCMAIN 93-07-26-xx/00, GUM 93-07-26/00
- Hitachi Virtual Storage Platform One Block 23 before DKCMAIN A3-04-02-xx/00, EMS A3-04-02/00
- Hitachi Virtual Storage Platform One Block 24 before DKCMAIN A3-04-02-xx/00, EMS A3-04-02/00
- Hitachi Virtual Storage Platform One Block 26 before DKCMAIN A3-04-02-xx/00, EMS A3-04-02/00
- Hitachi Virtual Storage Platform One Block 28 before DKCMAIN A3-04-02-xx/00, EMS A3-04-02/00
Timeline
- 2026-03-27: advisory: Initial vendor advisory published by Hitachi
- 2026-05-07: disclosed: CVE published to NVD