CVE-2025-7737

Hitachi · Virtual Storage Platform

A denial-of-service (DoS) vulnerability exists in the 10G iSCSI interface of the Hitachi Virtual Storage Platform, potentially allowing an attacker to disrupt storage availability.

Executive summary

A high-severity denial-of-service vulnerability in the Hitachi Virtual Storage Platform 10G iSCSI interface poses a significant risk to storage availability and business continuity.

Vulnerability

This vulnerability affects the 10G iSCSI interface, which is susceptible to a denial-of-service condition. The authentication requirements remain unverified; however, network-level access to the iSCSI interface is likely required for successful exploitation.

Business impact

The exploitation of this vulnerability could lead to a complete loss of access to critical storage resources, resulting in significant operational downtime. With a CVSS score of 8.6, this flaw is categorized as high severity due to the high impact on system availability, which could severely disrupt business processes relying on the storage platform.

Remediation

Immediate Action: Consult the official Hitachi security portal immediately to identify and apply the relevant firmware patches or configuration changes.

Proactive Monitoring: Monitor storage array logs for unusual spikes in traffic or recurring connection resets on the 10G iSCSI interfaces.

Compensating Controls: Ensure the storage management network is strictly segmented and restricted via firewall rules to authorized management and host IPs only.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Given the critical role of storage infrastructure, this vulnerability should be prioritized for remediation. Administrators must verify their firmware versions against the vendor’s guidance and apply the necessary patches immediately to prevent potential service disruptions.