CVE-2025-1978

8.3

Hitachi Storage · Virtual Storage Platform Multiple Products

A remote code execution vulnerability affects Hitachi Storage Navigator and the maintenance console in multiple Virtual Storage Platform models, allowing unauthenticated attackers to execute arbitrary code.

Executive summary

A critical remote code execution vulnerability affects multiple Hitachi Virtual Storage Platform models through Storage Navigator and maintenance console interfaces, posing a severe risk of complete infrastructure compromise.

Vulnerability

This is an improper control of generation of code flaw, categorized under CWE-94, which permits unauthenticated remote attackers to achieve code injection and subsequent remote code execution with network access required.

Business impact

A successful exploit of this vulnerability can allow an unauthenticated attacker to gain unauthorized control over core storage management consoles, potentially leading to data manipulation, complete system disruption, or total compromise of enterprise storage arrays. With a CVSS score of 8.3, this high severity rating reflects the potential for severe operational impact and data confidentiality breaches across critical storage infrastructure.

Remediation

Immediate Action: Apply the vendor-supplied security patches immediately for all internet-facing and internal storage management systems.

Proactive Monitoring: Monitor network traffic for unauthorized access attempts targeting Storage Navigator or maintenance console endpoints, and review administrative access logs for anomalies.

Compensating Controls: Restrict network access to Storage Navigator and maintenance console interfaces using strict firewall rules and network segmentation while waiting to apply official updates.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Administrators must prioritize the immediate application of firmware and software updates provided by Hitachi to address the underlying code injection flaw. Because these management interfaces govern core storage hardware, leaving them unpatched exposes the enterprise to critical infrastructure takeover.

More Hitachi Storage CVEs

Sources

Originally found and disclosed by Thomas Josef Riedmaier, Siemens Energy., per the CVE Program record.