CVE-2025-1978
Last modified
CVE-2025-1978 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Remote Code Execution Vulnerability in Hitachi Storage Navigator and the maintenance console in Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, Hitachi Virtual Storage Platform One Block 23, One Block 24, One Block 26, One Block 28. This issue affects Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, Hitachi Virtual Storage Platform One Block 23, One Block 24, One Block 26, One Block 28 : before DKCMAIN Ver. 88-08-16-xx/00, SVP Ver. EPSS estimates a 0.55% chance of exploitation in the next 30 days.
Description
Remote Code Execution Vulnerability in Hitachi Storage Navigator and the maintenance console in Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, Hitachi Virtual Storage Platform One Block 23, One Block 24, One Block 26, One Block 28. This issue affects Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, Hitachi Virtual Storage Platform One Block 23, One Block 24, One Block 26, One Block 28 : before DKCMAIN Ver. 88-08-16-xx/00, SVP Ver. 88-08-18-xx/00, before DKCMAIN Ver. 93-07-26-xx/00, SVP Ver. 93-07-26-xx/00, before DKCMAIN Ver. A3-04-02-xx/00, MPC Ver. A3-04-02-xx/00, before DKCMAIN Ver. A3-03-41-xx/00, MPC Ver. A3-03-41-xx/00, before DKCMAIN Ver. A3-03-03-xx/00, MPC Ver. A3-03-03-xx/00.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hitachi | Virtual Storage One Block | 23 |
| Hitachi | Virtual Storage One Block | 24 |
| Hitachi | Virtual Storage One Block | 26 |
| Hitachi | Virtual Storage One Block | 28 |
| Hitachi | Vsp G130 Firmware | All versions |
| Hitachi | Vsp G150 Firmware | All versions |
| Hitachi | Vsp G350 Firmware | All versions |
| Hitachi | Vsp G370 Firmware | All versions |
| Hitachi | Vsp G700 Firmware | All versions |
| Hitachi | Vsp G900 Firmware | All versions |
| Hitachi | Vsp F350 Firmware | All versions |
| Hitachi | Vsp F370 Firmware | All versions |
| Hitachi | Vsp F700 Firmware | All versions |
| Hitachi | Vsp F900 Firmware | All versions |
| Hitachi | Vsp E390 Firmware | All versions |
| Hitachi | Vsp E590 Firmware | All versions |
| Hitachi | Vsp E790 Firmware | All versions |
| Hitachi | Vsp E990 Firmware | All versions |
| Hitachi | Vsp E1090 Firmware | All versions |
| Hitachi | Vsp E390h Firmware | All versions |
| Hitachi | Vsp E590h Firmware | All versions |
| Hitachi | Vsp E790h Firmware | All versions |
| Hitachi | Vsp E1090h Firmware | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-1978?
How severe is CVE-2025-1978?
How do I fix CVE-2025-1978?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-1972The Export and Import Users and Customers plugin for WordPre…6.5
- CVE-2025-1973The Export and Import Users and Customers plugin for WordPre…4.9
- CVE-2025-1974A security issue was discovered in Kubernetes where under ce…9.8
- CVE-2025-1975A vulnerability in the Ollama server version 0.5.11 allows a…7.5
- CVE-2025-1976Brocade Fabric OS versions starting with 9.1.0 have root acc…6.7
- CVE-2025-1977The NPort 6100-G2/6200-G2 Series is affected by an execution…7.7
- CVE-2025-1979Versions of the package ray before 2.43.0 are vulnerable to …6.4
- CVE-2025-1980The Ready_ application's Profile section allows users to upl…9.4
- CVE-2025-1981Improper neutralization of input provided by a low-privilege…9.4
- CVE-2025-1982Local File Inclusion vulnerability in Ready's attachment upl…7.1
- CVE-2025-1983A cross-site scripting (XSS) vulnerability in Ready_'s File …5.1
- CVE-2025-1984Xerox Desktop Print Experience application contains a Local …5.2
Are you affected by CVE-2025-1978?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
