PT-2026-38349 · Hitachi · One Block 28+23

Published

2026-05-07

·

Updated

2026-05-07

·

CVE-2025-1978

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, One Block 23, One Block 24, One Block 26, One Block 28 versions prior to DKCMAIN Ver. 88-08-16-xx/00 and SVP Ver. 88-08-18-xx/00 Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, One Block 23, One Block 24, One Block 26, One Block 28 versions prior to DKCMAIN Ver. 93-07-26-xx/00 and SVP Ver. 93-07-26-xx/00 Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, One Block 23, One Block 24, One Block 26, One Block 28 versions prior to DKCMAIN Ver. A3-04-02-xx/00 and MPC Ver. A3-04-02-xx/00 Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, One Block 23, One Block 24, One Block 26, One Block 28 versions prior to DKCMAIN Ver. A3-03-41-xx/00 and MPC Ver. A3-03-41-xx/00 Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, One Block 23, One Block 24, One Block 26, One Block 28 versions prior to DKCMAIN Ver. A3-03-03-xx/00 and MPC Ver. A3-03-03-xx/00
Description Remote Code Execution is possible in Hitachi Storage Navigator and the maintenance console.
Recommendations Update to DKCMAIN Ver. 88-08-16-xx/00 and SVP Ver. 88-08-18-xx/00 or later. Update to DKCMAIN Ver. 93-07-26-xx/00 and SVP Ver. 93-07-26-xx/00 or later. Update to DKCMAIN Ver. A3-04-02-xx/00 and MPC Ver. A3-04-02-xx/00 or later. Update to DKCMAIN Ver. A3-03-41-xx/00 and MPC Ver. A3-03-41-xx/00 or later. Update to DKCMAIN Ver. A3-03-03-xx/00 and MPC Ver. A3-03-03-xx/00 or later.

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-1978

Affected Products

One Block 23
One Block 24
One Block 26
One Block 28
Storage Navigator
Virtual Storage Platform E1090
Virtual Storage Platform E1090H
Virtual Storage Platform E390
Virtual Storage Platform E390H
Virtual Storage Platform E590
Virtual Storage Platform E590H
Virtual Storage Platform E790
Virtual Storage Platform E790H
Virtual Storage Platform E990
Virtual Storage Platform F350
Virtual Storage Platform F370
Virtual Storage Platform F700
Virtual Storage Platform F900
Virtual Storage Platform G130
Virtual Storage Platform G150
Virtual Storage Platform G350
Virtual Storage Platform G370
Virtual Storage Platform G700
Virtual Storage Platform G900