CVE-2026-3314
BaseFortify
Publication date: 2026-05-26
Last updated on: 2026-05-26
Assigner: Hitachi, Ltd.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| hitachi | ops_center_analyzer | From 10.0.0-00 (inc) to 11.0.8-00 (exc) |
| hitachi | ops_center_analyzer_viewpoint | From 10.8.1-00 (inc) to 11.0.8-00 (exc) |
| hitachi | infrastructure_analytics_advisor | From 3.2.0-00 (inc) to 11.0.8-00 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-549 | The product does not mask passwords during entry, increasing the potential for attackers to observe and capture passwords. |
Attack-Flow Graph
AI Powered Q&A
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
The vulnerability involves missing password field masking in Hitachi Ops Center Analyzer and related products, which could expose sensitive password information to unauthorized users.
Exposure of sensitive password information may lead to non-compliance with data protection regulations such as GDPR and HIPAA, which require protection of sensitive authentication credentials to ensure confidentiality and prevent unauthorized access.
Therefore, this vulnerability could negatively impact compliance with these common standards by increasing the risk of unauthorized disclosure of sensitive information.
Can you explain this vulnerability to me?
CVE-2026-3314 is a vulnerability in Hitachi Infrastructure Analytics Advisor, Hitachi Ops Center Analyzer, and Hitachi Ops Center Analyzer viewpoint where passwords are not properly masked in the user interface.
This means that when users enter passwords in these products, the passwords may be visible instead of being hidden or obscured, potentially exposing sensitive password information to unauthorized users.
How can this vulnerability impact me? :
The vulnerability could potentially expose sensitive password information to unauthorized users, which may lead to unauthorized access if attackers obtain these passwords.
Since the passwords are not masked, anyone with access to the user interface could see the passwords in plain text, increasing the risk of credential compromise.
What immediate steps should I take to mitigate this vulnerability?
To mitigate this vulnerability, users are advised to upgrade affected products to the fixed versions.
- Upgrade Hitachi Ops Center Analyzer and Hitachi Ops Center Analyzer viewpoint to version 11.0.8-00 or later.
- Upgrade Hitachi Infrastructure Analytics Advisor to version 11.0.8-00 or later.
No workarounds are provided for this vulnerability, so upgrading is the only recommended immediate action.