CVE Feed

    Dashboard / CVE / CVE-2025-2902

    CVE-2025-2902

    Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform. This issue affects Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H: before DKCMAIN Ver. 93-07-26-xx/00, GUM Ver. 93-07-26/00; Hitachi Virtual Storage Platform 5100, 5500, 5100H, 5500H, 5200, 5600, 5200H, 5600H: before DKCMAIN Ver. 90-09-27-00/00, GUM Ver. 90-09-27/00; Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900: before DKCMAIN Ver. 88-08-16-xx/00, GUM Ver. 88-08-20/00.

    Published:Jun 29, 2026
    Last Modified:Jun 29, 2026
    EPS:Jun 29, 2026
    EPSS Score:0.00195
    CVSS Score:8.3

    Affected Products

    Vendor
    Hitachi
    Product
    5100
    Vendor
    Hitachi
    Product
    5100h
    Vendor
    Hitachi
    Product
    5200
    Vendor
    Hitachi
    Product
    5200h
    Vendor
    Hitachi
    Product
    5500
    Vendor
    Hitachi
    Product
    5500h
    Vendor
    Hitachi
    Product
    5600
    Vendor
    Hitachi
    Product
    5600h
    Vendor
    Hitachi
    Product
    E1090
    Vendor
    Hitachi
    Product
    E1090h
    Vendor
    Hitachi
    Product
    E390
    Vendor
    Hitachi
    Product
    E390h
    Vendor
    Hitachi
    Product
    E590
    Vendor
    Hitachi
    Product
    E590h
    Vendor
    Hitachi
    Product
    E790
    Vendor
    Hitachi
    Product
    E790h
    Vendor
    Hitachi
    Product
    E990
    Vendor
    Hitachi
    Product
    F350
    Vendor
    Hitachi
    Product
    F370
    Vendor
    Hitachi
    Product
    F700
    Vendor
    Hitachi
    Product
    F900
    Vendor
    Hitachi
    Product
    G130
    Vendor
    Hitachi
    Product
    G150
    Vendor
    Hitachi
    Product
    G350
    Vendor
    Hitachi
    Product
    G370
    Vendor
    Hitachi
    Product
    G700
    Vendor
    Hitachi
    Product
    G900

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High