OS command injection vulneravility in the management gui (maintenance utility) of Hitachi Virtual Storage Platform One Block 23, 24, 26 and 28.

This issue affects Hitachi Virtual Storage Platform One Block 23/24/26/28: before DKCMAIN A3-04-21-40/00, ESM A3-04-21/00.

Project Subscriptions

Vendors Products
Hitachi Subscribe
Hitachi Virtual Storage Platform One Block 23 Subscribe
Hitachi Virtual Storage Platform One Block 24 Subscribe
Hitachi Virtual Storage Platform One Block 26 Subscribe
Hitachi Virtual Storage Platform One Block 28 Subscribe
Virtual Storage One Block Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 08 May 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Hitachi virtual Storage One Block
CPEs cpe:2.3:a:hitachi:virtual_storage_one_block:23:*:*:*:*:*:*:*
cpe:2.3:a:hitachi:virtual_storage_one_block:24:*:*:*:*:*:*:*
cpe:2.3:a:hitachi:virtual_storage_one_block:26:*:*:*:*:*:*:*
cpe:2.3:a:hitachi:virtual_storage_one_block:28:*:*:*:*:*:*:*
Vendors & Products Hitachi virtual Storage One Block

Thu, 07 May 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Hitachi
Hitachi hitachi Virtual Storage Platform One Block 23
Hitachi hitachi Virtual Storage Platform One Block 24
Hitachi hitachi Virtual Storage Platform One Block 26
Hitachi hitachi Virtual Storage Platform One Block 28
Vendors & Products Hitachi
Hitachi hitachi Virtual Storage Platform One Block 23
Hitachi hitachi Virtual Storage Platform One Block 24
Hitachi hitachi Virtual Storage Platform One Block 26
Hitachi hitachi Virtual Storage Platform One Block 28

Thu, 07 May 2026 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 07 May 2026 07:30:00 +0000

Type Values Removed Values Added
Description OS command injection vulneravility in the management gui (maintenance utility) of Hitachi Virtual Storage Platform One Block 23, 24, 26 and 28. This issue affects Hitachi Virtual Storage Platform One Block 23/24/26/28: before DKCMAIN A3-04-21-40/00, ESM A3-04-21/00.
Title OS command injection vulneravility in the management gui (maintenance utility) of Hitachi Virtual Storage Platform One Block 23/24/26/28
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Hitachi

Published:

Updated: 2026-05-07T13:02:35.204Z

Reserved: 2025-08-29T07:14:42.691Z

Link: CVE-2025-9661

cve-icon Vulnrichment

Updated: 2026-05-07T13:02:22.155Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-07T08:16:00.317

Modified: 2026-05-08T16:59:28.053

Link: CVE-2025-9661

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-07T21:25:03Z

Weaknesses