CVE-2025-2902
Last modified
CVE-2025-2902 is a high-severity vulnerability rated 8.3/10 on the CVSS scale. Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform. This issue affects Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H: before DKCMAIN Ver. 93-07-26-xx/00, GUM Ver. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform. This issue affects Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H: before DKCMAIN Ver. 93-07-26-xx/00, GUM Ver. 93-07-26/00; Hitachi Virtual Storage Platform 5100, 5500, 5100H, 5500H, 5200, 5600, 5200H, 5600H: before DKCMAIN Ver. 90-09-27-00/00, GUM Ver. 90-09-27/00; Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900: before DKCMAIN Ver. 88-08-16-xx/00, GUM Ver. 88-08-20/00.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Hitachi | Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H | < DKCMAIN Ver. 93-07-26-xx/00, GUM Ver. 93-07-26/00 |
| Hitachi | Hitachi Virtual Storage Platform 5100, 5500, 5100H, 5500H, 5200, 5600, 5200H, 5600H | < DKCMAIN Ver. 90-09-27-00/00, GUM Ver. 90-09-27/00 |
| Hitachi | Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900 | < DKCMAIN Ver. 88-08-16-xx/00, GUM Ver. 88-08-20/00 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-2902?
How severe is CVE-2025-2902?
How do I fix CVE-2025-2902?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-29012Missing Authorization vulnerability in kamleshyadav CF7 7 Ma…5.3
- CVE-2025-29013Missing Authorization vulnerability in faaiq Custom Category…5.4
- CVE-2025-29014Improper Neutralization of Input During Web Page Generation …7.1
- CVE-2025-29015Code Astro Internet Banking System 2.0.0 is vulnerable to Cr…6.1
- CVE-2025-29017A Remote Code Execution (RCE) vulnerability exists in Code A…8.8
- CVE-2025-29018A Stored Cross-Site Scripting (XSS) vulnerability exists in …4.8
- CVE-2025-29029Tenda AC6 v15.03.05.16 was discovered to contain a buffer ov…9.8
- CVE-2025-2903An attacker with knowledge of creating user accounts during …8.5
- CVE-2025-29030Tenda AC6 v15.03.05.16 was discovered to contain a buffer ov…9.8
- CVE-2025-29031Tenda AC6 v15.03.05.16 was discovered to contain a buffer ov…9.8
- CVE-2025-29032Tenda AC9 v15.03.05.19(6318) was discovered to contain a buf…5.9
- CVE-2025-29033An issue in BambooHR Build v.25.0210.170831-83b08dd allows a…7.3
Are you affected by CVE-2025-2902?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
