CVE-2025-1978

Remote Code Execution Vulnerability in Hitachi Storage Navigator and the maintenance console in Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, Hitachi Virtual Storage Platform One Block 23, One Block 24, One Block 26, One Block 28. This issue affects Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, Hitachi Virtual Storage Platform One Block 23, One Block 24, One Block 26, One Block 28  : before DKCMAIN Ver. 88-08-16-xx/00, SVP Ver. 88-08-18-xx/00, before DKCMAIN Ver. 93-07-26-xx/00, SVP Ver. 93-07-26-xx/00, before DKCMAIN Ver. A3-04-02-xx/00, MPC Ver. A3-04-02-xx/00, before DKCMAIN Ver. A3-03-41-xx/00, MPC Ver. A3-03-41-xx/00, before DKCMAIN Ver. A3-03-03-xx/00, MPC Ver. A3-03-03-xx/00.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hitachi:virtual_storage_one_block:23:*:*:*:*:*:*:*
cpe:2.3:a:hitachi:virtual_storage_one_block:24:*:*:*:*:*:*:*
cpe:2.3:a:hitachi:virtual_storage_one_block:26:*:*:*:*:*:*:*
cpe:2.3:a:hitachi:virtual_storage_one_block:28:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:hitachi:vsp_g130_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hitachi:vsp_g130:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:hitachi:vsp_g150_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hitachi:vsp_g150:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:hitachi:vsp_g350_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hitachi:vsp_g350:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:hitachi:vsp_g370_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hitachi:vsp_g370:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:hitachi:vsp_g700_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hitachi:vsp_g700:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:hitachi:vsp_g900_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hitachi:vsp_g900:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:hitachi:vsp_f350_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hitachi:vsp_f350:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:hitachi:vsp_f370_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hitachi:vsp_f370:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:hitachi:vsp_f700_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hitachi:vsp_f700:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:hitachi:vsp_f900_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hitachi:vsp_f900:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:hitachi:vsp_e390_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hitachi:vsp_e390:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:hitachi:vsp_e590_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hitachi:vsp_e590:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:hitachi:vsp_e790_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hitachi:vsp_e790:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:hitachi:vsp_e990_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hitachi:vsp_e990:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:hitachi:vsp_e1090_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hitachi:vsp_e1090:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:hitachi:vsp_e390h_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hitachi:vsp_e390h:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:hitachi:vsp_e590h_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hitachi:vsp_e590h:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:hitachi:vsp_e790h_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hitachi:vsp_e790h:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:hitachi:vsp_e1090h_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hitachi:vsp_e1090h:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-05-07 09:16

Updated : 2026-06-17 08:40


NVD link : CVE-2025-1978

Mitre link : CVE-2025-1978

CVE.ORG link : CVE-2025-1978


JSON object : View

Products Affected

hitachi

  • vsp_e590h
  • vsp_f370
  • vsp_g370
  • vsp_f700
  • vsp_e790_firmware
  • vsp_e390h_firmware
  • vsp_e990_firmware
  • vsp_e390
  • vsp_e590
  • vsp_e990
  • vsp_g700
  • vsp_e1090_firmware
  • vsp_f350_firmware
  • vsp_g150
  • vsp_e1090h_firmware
  • vsp_e1090
  • vsp_f350
  • vsp_e390h
  • vsp_g130_firmware
  • vsp_g350_firmware
  • vsp_g900
  • vsp_f900_firmware
  • vsp_e390_firmware
  • vsp_g900_firmware
  • virtual_storage_one_block
  • vsp_e1090h
  • vsp_e590h_firmware
  • vsp_f900
  • vsp_e590_firmware
  • vsp_g370_firmware
  • vsp_e790h
  • vsp_f370_firmware
  • vsp_g700_firmware
  • vsp_g350
  • vsp_f700_firmware
  • vsp_e790h_firmware
  • vsp_g130
  • vsp_e790
  • vsp_g150_firmware
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')