Junglewise Threat Intelligence

CVE-2025-7737: Hitachi Virtual Storage Platform DoS in 10G iSCSI Interface

CVE-2025-7737 · Severity: high · CVSS 8.6 · Published 2026-06-19

Technologies: Hitachi Virtual Storage Platform E-Series. Vendors: Hitachi.

Executive brief

A vulnerability in the 10G iSCSI interface of Hitachi Virtual Storage Platforms could allow an attacker to cause a denial-of-service condition. These storage systems are used by enterprises to manage and store critical business data. If exploited, the storage interface may become unresponsive, potentially disrupting access to data and causing operational downtime for applications relying on the storage array.

Technical details

A denial-of-service vulnerability exists in the 10G iSCSI interface of various Hitachi Virtual Storage Platform (VSP) models. The flaw is categorized as CWE-770 (Allocation of Resources Without Limits or Throttling), where the iSCSI port becomes unresponsive when it receives a large number of malicious packets. This is a network-based attack that requires no authentication or user interaction. Successful exploitation results in a complete loss of availability for the affected iSCSI interface. Hitachi has released updated microcode (DKCMAIN and CHB/ISFC versions) to mitigate this issue across the affected E, G, F, 5000, and VX series platforms.

Affected products

  • Hitachi Virtual Storage Platform E-Series (E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H) before DKCMAIN Ver.93-07-21-80/00-05, CHB(iSCSI) Ver.88-01-02-04
  • Hitachi Virtual Storage Platform G-Series (G100, G130, G150, G200, G350, G370, G400, G600, G700, G800, G900, G1000, G1500) Multiple versions; see advisory for specific DKCMAIN and CHB/ISFC combinations
  • Hitachi Virtual Storage Platform F-Series (F350, F370, F400, F600, F700, F800, F900, F1500) Multiple versions; see advisory for specific DKCMAIN and CHB/ISFC combinations
  • Hitachi Virtual Storage Platform 5000 Series (5100, 5500, 5100H, 5500H, 5200, 5600, 5200H, 5600H) before DKCMAIN Ver.90-09-01-00/01-01, CHB(iSCSI) Ver.90-01-01-07
  • Hitachi Virtual Storage Platform VX7, VX8 before DKCMAIN Ver.80-06-93-00/00-04, ISFC Ver.80-01-17

Timeline

  • 2026-06-11: advisory: Initial advisory published by Hitachi
  • 2026-06-19: disclosed: CVE published to NVD dataset

References

Related threats