CVE-2025-9661
8.1Hitachi · Virtual Storage Platform One Block
An OS command injection vulnerability exists in the management GUI maintenance utility of Hitachi Virtual Storage Platform One Block devices.
Executive summary
An OS command injection vulnerability in the management GUI maintenance utility of Hitachi Virtual Storage Platform One Block devices allows remote attackers to execute arbitrary system commands.
Vulnerability
This is an OS command injection flaw (CWE-78) residing in the management GUI maintenance utility, allowing unauthenticated attackers to execute arbitrary OS commands via the network vector.
Business impact
A successful exploit of this vulnerability can lead to a complete compromise of the underlying storage controller operating system, resulting in total loss of confidentiality, integrity, and availability. With a CVSS score of 8.1, the high severity reflects the potential for severe business disruption, unauthorized data access, and complete administrative takeover of critical storage infrastructure.
Remediation
Immediate Action: Apply the vendor security updates provided by Hitachi, updating firmware to DKCMAIN A3-04-21-40/00 and ESM A3-04-21/00 or later.
Proactive Monitoring: Monitor management GUI access logs for unusual administrative login patterns, unauthorized session creation, or unexpected shell execution artifacts.
Compensating Controls: Restrict management GUI access strictly to dedicated, trusted internal management networks and employ network segmentation or firewalls to block untrusted external access.
Exploitation status
Public Exploit Available: false / unknown
Analyst recommendation
Given the critical nature of storage infrastructure and the high CVSS score, administrators must prioritize applying the designated firmware updates. Until patches can be deployed, ensure strict perimeter defenses and network segmentation restrict exposure of the management GUI to unauthorized entities.