CVE-2025-1978
CRITICAL WAF: MediumRemote Code Execution Vulnerability in Hitachi Storage Navigator and the maintenance console in Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, Hitachi Virtual Storage Platform One Block 23, One Block 24, One Block 26, One Block 28. This issue affects Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, Hitachi Virtual Storage Platform One Block 23, One Block 24, One Block 26, One Block 28 : before DKCMAIN Ver. 88-08-16-xx/00, SVP Ver. 88-08-18-xx/00, before DKCMAIN Ver. 93-07-26-xx/00, SVP Ver. 93-07-26-xx/00, before DKCMAIN Ver. A3-04-02-xx/00, MPC Ver. A3-04-02-xx/00, before DKCMAIN Ver. A3-03-41-xx/00, MPC Ver. A3-03-41-xx/00, before DKCMAIN Ver. A3-03-03-xx/00, MPC Ver. A3-03-03-xx/00.
WAF Coverage Analysis
OWASP: A03:2021 Injection
Affected Software
| Vendor | Product | Version |
|---|---|---|
| hitachi | virtual_storage_one_block | 23 |
| hitachi | virtual_storage_one_block | 24 |
| hitachi | virtual_storage_one_block | 26 |
| hitachi | virtual_storage_one_block | 28 |
| hitachi | vsp_g130_firmware | - |
| hitachi | vsp_g150_firmware | - |
| hitachi | vsp_g350_firmware | - |
| hitachi | vsp_g370_firmware | - |
| hitachi | vsp_g700_firmware | - |
| hitachi | vsp_g900_firmware | - |
References
- www.hitachi.com (Vendor Advisory)