CVE-2025-2902: Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform
Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform.
This issue affects Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H: before DKCMAIN Ver. 93-07-26-xx/00, GUM Ver. 93-07-26/00; Hitachi Virtual Storage Platform 5100, 5500, 5100H, 5500H, 5200, 5600, 5200H, 5600H: before DKCMAIN Ver. 90-09-27-00/00, GUM Ver. 90-09-27/00; Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900: before DKCMAIN Ver. 88-08-16-xx/00, GUM Ver. 88-08-20/00.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2902?
The severity of CVE-2025-2902 is classified as high with a score of 8.3.
How do I fix CVE-2025-2902?
To fix CVE-2025-2902, update the Hitachi Virtual Storage Platform to DKCMAIN Ver. 93-07-26-xx/00 or GUM Ver. 93-07-26/00.
What are the affected products for CVE-2025-2902?
The affected products for CVE-2025-2902 include Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, and their H variants.
What type of vulnerability is CVE-2025-2902?
CVE-2025-2902 is an improper authorization vulnerability affecting the maintenance utility in Hitachi Virtual Storage Platform.
What is the impact of CVE-2025-2902?
The impact of CVE-2025-2902 includes the potential for unauthorized access to sensitive functions within the affected storage platforms.