GHSA-rprw-c6w3-xx2q · Severity: high — Remote Code Execution Vulnerability in Hitachi Storage Navigator and the maintenance console in...
Remote Code Execution Vulnerability in Hitachi Storage Navigator and the maintenance console in Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, Hitachi Virtual Storage Platform One Block 23, One Block 24, One Block 26, One Block 28. This issue affects Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, Hitachi Virtual Storage Platform One Block 23, One Block 24, One Block 26, One Block 28 : before DKCMAIN Ver. 88-08-16-xx/00, SVP Ver. 88-08-18-xx/00, before DKCMAIN Ver. 93-07-26-xx/00, SVP Ver. 93-07-26-xx/00, before DKCMAIN Ver. A3-04-02-xx/00, MPC Ver. A3-04-02-xx/00, before DKCMAIN Ver. A3-03-41-xx/00, MPC Ver. A3-03-41-xx/00, before DKCMAIN Ver. A3-03-03-xx/00, MPC Ver. A3-03-03-xx/00.
Conclusion & alert: CVE-2025-1978 is rated Moderate Risk (43.1/100): CVSS High severity, with low exploitation likelihood (EPSS 0.11%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-22 | 0.29% | 0.11% | -0.18% |
| 2 | 2026-05-13 | 0.22% | 0.29% | +0.07% |
| 3 | 2026-05-07 | — | 0.22% | — |
Full EPSS history (3 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.3 | 3.1 | HIGH |
|
3.9 | 3.7 | [email protected] |
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
GHSA-rprw-c6w3-xx2q · Severity: high — Remote Code Execution Vulnerability in Hitachi Storage Navigator and the maintenance console in...
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| hitachi | virtual_storage_one_block | 23 | cpe:2.3:a:hitachi:virtual_storage_one_block:23:*:*:*:*:*:*:* |
| hitachi | virtual_storage_one_block | 24 | cpe:2.3:a:hitachi:virtual_storage_one_block:24:*:*:*:*:*:*:* |
| hitachi | virtual_storage_one_block | 26 | cpe:2.3:a:hitachi:virtual_storage_one_block:26:*:*:*:*:*:*:* |
| hitachi | virtual_storage_one_block | 28 | cpe:2.3:a:hitachi:virtual_storage_one_block:28:*:*:*:*:*:*:* |
| hitachi | vsp_g130_firmware | — | cpe:2.3:o:hitachi:vsp_g130_firmware:-:*:*:*:*:*:*:* |
| hitachi | vsp_g150_firmware | — | cpe:2.3:o:hitachi:vsp_g150_firmware:-:*:*:*:*:*:*:* |
| hitachi | vsp_g350_firmware | — | cpe:2.3:o:hitachi:vsp_g350_firmware:-:*:*:*:*:*:*:* |
| hitachi | vsp_g370_firmware | — | cpe:2.3:o:hitachi:vsp_g370_firmware:-:*:*:*:*:*:*:* |
| hitachi | vsp_g700_firmware | — | cpe:2.3:o:hitachi:vsp_g700_firmware:-:*:*:*:*:*:*:* |
| hitachi | vsp_g900_firmware | — | cpe:2.3:o:hitachi:vsp_g900_firmware:-:*:*:*:*:*:*:* |
| hitachi | vsp_f350_firmware | — | cpe:2.3:o:hitachi:vsp_f350_firmware:-:*:*:*:*:*:*:* |
| hitachi | vsp_f370_firmware | — | cpe:2.3:o:hitachi:vsp_f370_firmware:-:*:*:*:*:*:*:* |
| hitachi | vsp_f700_firmware | — | cpe:2.3:o:hitachi:vsp_f700_firmware:-:*:*:*:*:*:*:* |
| hitachi | vsp_f900_firmware | — | cpe:2.3:o:hitachi:vsp_f900_firmware:-:*:*:*:*:*:*:* |
| hitachi | vsp_e390_firmware | — | cpe:2.3:o:hitachi:vsp_e390_firmware:-:*:*:*:*:*:*:* |
| hitachi | vsp_e590_firmware | — | cpe:2.3:o:hitachi:vsp_e590_firmware:-:*:*:*:*:*:*:* |
| hitachi | vsp_e790_firmware | — | cpe:2.3:o:hitachi:vsp_e790_firmware:-:*:*:*:*:*:*:* |
| hitachi | vsp_e990_firmware | — | cpe:2.3:o:hitachi:vsp_e990_firmware:-:*:*:*:*:*:*:* |
| hitachi | vsp_e1090_firmware | — | cpe:2.3:o:hitachi:vsp_e1090_firmware:-:*:*:*:*:*:*:* |
| hitachi | vsp_e390h_firmware | — | cpe:2.3:o:hitachi:vsp_e390h_firmware:-:*:*:*:*:*:*:* |
| hitachi | vsp_e590h_firmware | — | cpe:2.3:o:hitachi:vsp_e590h_firmware:-:*:*:*:*:*:*:* |
| hitachi | vsp_e790h_firmware | — | cpe:2.3:o:hitachi:vsp_e790h_firmware:-:*:*:*:*:*:*:* |
| hitachi | vsp_e1090h_firmware | — | cpe:2.3:o:hitachi:vsp_e1090h_firmware:-:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://www.hitachi.com/products/it/storage-solutions/sec_info/2026/2026_307.html | Vendor Advisory |