Back to overview

CVE-2025-7386

MEDIUM
6.8
CVSS 3.1
Description
Information exposure vulnerability in Hitachi Storage Navigator. This issue affects Hitachi Virtual Storage Platform 5100, 5200, 5500, 5600, 5100H, 5200H, 5500H, 5600H, VX8: before DKCMAIN Ver. 90-09-24-00/00, SVP Ver. 90-09-24/00, before DKCMAIN Ver. 90-08-86-00/00, SVP Ver. 90-08-86/00; Hitachi Virtual Storage Platform G1000, G1500, F1500, VX7: before DKCMAIN Ver. 80-06-96-00/00, SVP Ver. 80-06-91/00.

Metadata

CVE ID
CVE-2025-7386
State
PUBLISHED
Assigner
Hitachi
Reserved
2025-07-09 10:16 UTC
Published
2026-06-29 05:22 UTC
Last updated
2026-06-29 12:36 UTC
Primary CWE
CWE-522
CWE-522 Insufficiently Protected Credentials
Vendor / Product
Hitachi / Hitachi Virtual Storage Platform 5100, 5200, 5500, 5600, 5100H, 5200H, 5500H, 5600H, VX8
Sources
cve.org  ·  NVD

Severity & Metrics

6.8 MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
partial
Affected products (2)
VendorProductPlatformVersions
Hitachi Hitachi Virtual Storage Platform 5100, 5200, 5500, 5600, 5100H, 5200H, 5500H, 5600H, VX8 0 < DKCMAIN Ver. 90-09-24-00/00, SVP Ver. 90-09-24/00, 0 < DKCMAIN Ver. 90-08-86-00/00, SVP Ver. 90-08-86/00
Hitachi Hitachi Virtual Storage Platform G1000, G1500, F1500, VX7 0 < DKCMAIN Ver. 80-06-96-00/00, SVP Ver. 80-06-91/00
Weakness (CWE)
CWESourceDescription
CWE-522 cna CWE-522 Insufficiently Protected Credentials
CVSS scores (1)
ScoreSeverityVersionSourceVector
6.8 MEDIUM 3.1 cna CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Back to overview