Executive brief
A security vulnerability has been identified in the maintenance utility of Hitachi Virtual Storage Platforms, which are high-performance systems used for enterprise data storage and management. An attacker with low-level access to the management interface could perform unauthorized actions, potentially leading to data modification or service disruptions. This could impact the integrity of stored business data and the availability of critical storage services.
Technical details
An improper authorization vulnerability (CWE-862) exists in the management GUI (Maintenance Utility) of several Hitachi Virtual Storage Platform (VSP) models. The flaw allows a remote attacker with low-privileged credentials (PR:L) to bypass intended authorization checks. Successful exploitation can lead to unauthorized modification of system settings or data (I:H) and potential disruption of storage services (A:H). The vulnerability is addressed by updating the system microcode (DKCMAIN and GUM) to the versions specified in the manufacturer's advisory.
Affected products
- Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H before DKCMAIN Ver. 93-07-26-xx/00, GUM Ver. 93-07-26/00
- Hitachi Virtual Storage Platform 5100, 5500, 5100H, 5500H, 5200, 5600, 5200H, 5600H before DKCMAIN Ver. 90-09-27-00/00, GUM Ver. 90-09-27/00
- Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900 before DKCMAIN Ver. 88-08-16-xx/00, GUM Ver. 88-08-20/00
Timeline
- 2026-03-27: advisory: Initial advisory published by Hitachi
- 2026-06-29: disclosed: CVE published to NVD dataset