CVE-2025-66444

8.2

Hitachi · Infrastructure Analytics Advisor and Ops Center Analyzer

A stored Cross-site Scripting (XSS) vulnerability in Hitachi Infrastructure Analytics Advisor and Ops Center Analyzer allows attackers to execute arbitrary scripts in the context of user sessions.

Executive summary

A high-severity Cross-site Scripting vulnerability in Hitachi infrastructure management products allows for potential session hijacking and unauthorized script execution.

Vulnerability

This is a Cross-site Scripting (CWE-79) vulnerability where improper neutralization of user-supplied input occurs during web page generation. According to the CVSS vector (PR:L), an authenticated user with low privileges is required to trigger the exploit, which can result in compromised confidentiality and integrity.

Business impact

Successful exploitation could allow an attacker to inject malicious scripts into the web interface, potentially leading to unauthorized actions performed on behalf of legitimate users or the theft of session tokens. Given the administrative nature of these management products, this represents a significant risk to the integrity of the data center management environment. The CVSS score of 8.2 reflects the potential for significant impact on system operations and user security.

Remediation

Immediate Action: Administrators must review the vendor security advisory and apply the necessary patches for Hitachi Ops Center Analyzer to version 11.0.5-00 or later.

Proactive Monitoring: Security teams should monitor web server logs for suspicious URL patterns or unexpected script injections originating from the management interface.

Compensating Controls: Deploy or update Web Application Firewall (WAF) rules to inspect and filter malicious payloads targeting the web console, which may provide temporary protection until patching is completed.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Organizations utilizing Hitachi Infrastructure Analytics Advisor or Ops Center Analyzer must prioritize this update to prevent potential lateral movement or session compromise. Please consult the official Hitachi security portal referenced in the metadata to verify the specific patch path for your environment and ensure all management nodes are updated promptly.

More Hitachi CVEs

Sources