PatchSiren cyber security CVE debrief
CVE-2025-2902 Hitachi CVE debrief
CVE-2025-2902 is an Improper Authorization Vulnerability in the Maintenance Utility of Hitachi Virtual Storage Platform. The vulnerability affects multiple models of Hitachi Virtual Storage Platform, including E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, 5100, 5500, 5100H, 5500H, 5200, 5600, 5200H, 5600H, G130, G150, G350, G370, G700, G900, F350, F370, F700, and F900. The vulnerability has a CVSS score of 8.3, indicating a high severity. The affected versions of the products are before DKCMAIN Ver. 93-07-26-xx/00, GUM Ver. 93-07-26/00 for E-series; before DKCMAIN Ver. 90-09-27-00/00, GUM Ver. 90-09-27/00 for 5100 and 5500 series; and before DKCMAIN Ver. 88-08-16-xx/00, GUM Ver. 88-08-20/00 for G and F series.
- Vendor
- Hitachi
- Product
- Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H
- CVSS
- HIGH 8.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-29
- Original CVE updated
- 2026-06-29
- Advisory published
- 2026-06-29
- Advisory updated
- 2026-06-29
Who should care
Organizations using Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, 5100, 5500, 5100H, 5500H, 5200, 5600, 5200H, 5600H, G130, G150, G350, G370, G700, G900, F350, F370, F700, and F900 should be aware of this vulnerability. The vulnerability has a high CVSS score of 8.3, indicating a high severity. Users of these products should review their inventory and apply the necessary patches or updates to mitigate the vulnerability.
Technical summary
The vulnerability is caused by improper authorization in the Maintenance Utility of Hitachi Virtual Storage Platform. This allows an attacker to perform unauthorized actions on the system. The vulnerability affects multiple models of Hitachi Virtual Storage Platform and has a CVSS score of 8.3. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H, indicating a high severity. The weakness associated with this vulnerability is CWE-862.
Defensive priority
High priority should be given to patching or updating the affected Hitachi Virtual Storage Platform models. Organizations should review their inventory and apply the necessary patches or updates to mitigate the vulnerability.
Recommended defensive actions
- Review inventory of Hitachi Virtual Storage Platform models E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, 5100, 5500, 5100H, 5500H, 5200, 5600, 5200H, 5600H, G130, G150, G350, G370, G700, G900, F350, F370,
- Apply patches or updates to DKCMAIN and GUM for affected models.
- Monitor system logs for suspicious activity.
- Implement compensating controls to limit access to the Maintenance Utility.
- Verify the integrity of system configurations.
Evidence notes
The CVE record and NVD detail provide information on the vulnerability, including its CVSS score and affected products. The source reference provides additional information from Hitachi on the vulnerability.
Official resources
-
CVE-2025-2902 CVE record
CVE.org
-
CVE-2025-2902 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
This article is AI-assisted and based on the supplied source corpus.