These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A Command Argument Injection Vulnerability exists in Cosminexus Component Container. This issue affects multiple versions of Cosminexus Component Container, from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through 11-10-11, from 11-00 through 11-00-12, from 09-87 before 0 [truncated]
A critical OS command injection vulnerability exists in Cosminexus Component Container. This issue affects multiple versions of Cosminexus Component Container, from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, and various other version ranges. The vulnerability has a CVSS score of 9.8 and is considered critical. The vulnerability allows attackers to execute arbitrary OS commands, potentially lead [truncated]
CVE-2026-71375 Improper restriction of XML external entity reference vulnerability in Cosminexus Component Container. The vulnerability affects multiple versions of Cosminexus Component Container, and defenders should assess exposure and potential impacts on systems using affected versions. The issue requires verification of exposure and assessment of potential impacts, and applying vendor-provided patche [truncated]
A deserialization of untrusted data vulnerability exists in Cosminexus Component Container. This issue affects multiple versions of Cosminexus Component Container, including 11-70-01 before 11-70-03, 11-60 before 11-60-03, and others. The vulnerability allows for potential code execution, which could lead to unauthorized access, data breaches, or system compromise. Defenders should prioritize verifying ex [truncated]
CVE-2025-2902 is an Improper Authorization Vulnerability in the Maintenance Utility of Hitachi Virtual Storage Platform. The vulnerability affects multiple models of Hitachi Virtual Storage Platform, including E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, 5100, 5500, 5100H, 5500H, 5200, 5600, 5200H, 5600H, G130, G150, G350, G370, G700, G900, F350, F370, F700, and F900. The vulnerability has [truncated]
CVE-2025-0824 is a low-severity vulnerability (CVSS Score: 3.7) affecting Hitachi Virtual Storage Platform One Block 23, 24, 26, and 28. The issue arises from a lack of validation for firmware updates. Affected versions include those before DKCMAIN A3-04-21-40/00, ESM A3-04-21/00. This vulnerability was disclosed on June 29, 2026. Users should verify their system versions and consider updating to the late [truncated]
A missing password field masking vulnerability in Hitachi Ops Center Analyzer and Hitachi Infrastructure Analytics Advisor products allows physical attackers to observe credentials entered into unmasked password fields. The CVSS 3.1 vector (AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) indicates this requires physical access to the device, with low attack complexity and no privileges required, resulting in high co [truncated]
CVE-2026-2072 is a Cross-Site Scripting vulnerability in Hitachi Infrastructure Analytics Advisor and Hitachi Ops Center Analyzer. The vulnerability has a CVSS score of 8.2 and is classified as HIGH. Affected versions include Hitachi Infrastructure Analytics Advisor: all versions; Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.5-00. Users should review the official CVE record and vendor advisory [truncated]
The CVE-2026-1166 record indicates an Open Redirect vulnerability in Hitachi Ops Center Administrator versions from 10.2.0 before 11.0.8. This issue has a CVSS score of 4.3 and is classified under CWE-601. The vulnerability was published on 2026-03-25T03:16:05.643Z and has not been modified since then. Security teams should be aware of this vulnerability and take necessary actions to mitigate the risk. Th [truncated]