CVE-2025-1978
8.3Hitachi Storage · Virtual Storage Platform Multiple Products
A remote code execution vulnerability affects Hitachi Storage Navigator and the maintenance console in multiple Virtual Storage Platform models, allowing unauthenticated attackers to execute arbitrary code.
Executive summary
A critical remote code execution vulnerability affects multiple Hitachi Virtual Storage Platform models through Storage Navigator and maintenance console interfaces, posing a severe risk of complete infrastructure compromise.
Vulnerability
This is an improper control of generation of code flaw, categorized under CWE-94, which permits unauthenticated remote attackers to achieve code injection and subsequent remote code execution with network access required.
Business impact
A successful exploit of this vulnerability can allow an unauthenticated attacker to gain unauthorized control over core storage management consoles, potentially leading to data manipulation, complete system disruption, or total compromise of enterprise storage arrays. With a CVSS score of 8.3, this high severity rating reflects the potential for severe operational impact and data confidentiality breaches across critical storage infrastructure.
Remediation
Immediate Action: Apply the vendor-supplied security patches immediately for all internet-facing and internal storage management systems.
Proactive Monitoring: Monitor network traffic for unauthorized access attempts targeting Storage Navigator or maintenance console endpoints, and review administrative access logs for anomalies.
Compensating Controls: Restrict network access to Storage Navigator and maintenance console interfaces using strict firewall rules and network segmentation while waiting to apply official updates.
Exploitation status
Public Exploit Available: false
Analyst recommendation
Administrators must prioritize the immediate application of firmware and software updates provided by Hitachi to address the underlying code injection flaw. Because these management interfaces govern core storage hardware, leaving them unpatched exposes the enterprise to critical infrastructure takeover.
More Hitachi Storage CVEs
Sources
Originally found and disclosed by Thomas Josef Riedmaier, Siemens Energy., per the CVE Program record.