Junglewise Threat Intelligence

CVE-2025-7386: Hitachi Storage Navigator information exposure in external authentication

CVE-2025-7386 · Severity: medium · CVSS 6.8 · Published 2026-06-29

Vendors: Hitachi.

Executive brief

Hitachi Storage Navigator, a management tool for high-end enterprise storage systems, contains a vulnerability that can expose sensitive authentication information. This occurs when the system is configured to use external authentication services. While the stored customer data on the disks remains secure, an attacker with high-level administrative privileges could potentially gain access to credentials or other sensitive configuration details, leading to further unauthorized access to the management interface.

Technical details

An information exposure vulnerability (CWE-522) exists in Hitachi Storage Navigator when configured for external authentication. The flaw allows an authenticated attacker with high privileges (PR:H) to access sensitive authentication-related information. The vulnerability is triggered during the authentication process with external providers. While the scope is changed (S:C), the impact is limited to confidentiality (C:H), with no direct impact on the integrity or availability of the storage system or the data stored on the disk arrays. Patches are available via micro-program updates for DKCMAIN and SVP components across affected Virtual Storage Platform (VSP) models.

Affected products

  • Hitachi Virtual Storage Platform 5100, 5200, 5500, 5600, 5100H, 5200H, 5500H, 5600H, VX8 DKCMAIN before 90-09-24-00/00 or 90-08-86-00/00; SVP before 90-09-24/00 or 90-08-86/00
  • Hitachi Virtual Storage Platform G1000, G1500, F1500, VX7 DKCMAIN before 80-06-96-00/00; SVP before 80-06-91/00

Timeline

  • 2026-03-12: advisory: Initial security information published by Hitachi
  • 2026-06-29: disclosed: CVE published to NVD dataset

References

Related threats