Executive brief
Hitachi Ops Center Analyzer and Infrastructure Analytics Advisor are data center management tools used to monitor and analyze storage infrastructure. A vulnerability exists where password fields are not properly masked, potentially allowing an unauthorized person with physical access to the console to view sensitive credentials. This could lead to unauthorized access to managed storage systems if an attacker observes a user entering their password or views it on an unattended screen.
Technical details
A missing password field masking vulnerability (CWE-549) exists in multiple Hitachi storage analytics products, specifically within the Ops Center Analyzer detail view, probe modules, and viewpoint components. The flaw allows sensitive credentials to be displayed in plaintext on the screen rather than being obscured by asterisks or dots. Exploitation requires physical access (AV:P) to the terminal or management console while a user is interacting with the affected fields. An attacker can gain unauthorized access to credentials, potentially leading to further compromise of the storage environment. The issue is resolved in version 11.0.8-00 across all affected product lines.
Affected products
- Hitachi Ops Center Analyzer 10.0.0-00 to 11.0.7-00
- Hitachi Ops Center Analyzer viewpoint 10.8.1-00 to 11.0.7-00
- Hitachi Infrastructure Analytics Advisor 3.2.0-00 to 11.0.7-00
Timeline
- 2026-05-26: disclosed
- 2026-05-26: advisory
- 2026-05-26: patched: Fixed in version 11.0.8-00