CVE-2025-7386
Received Received - Intake

Information Exposure in Hitachi Storage Navigator

Vulnerability report for CVE-2025-7386, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-06-29

Last updated on: 2026-06-29

Assigner: Hitachi, Ltd.

Description

Information exposure vulnerability in Hitachi Storage Navigator. This issue affects Hitachi Virtual Storage Platform 5100, 5200, 5500, 5600, 5100H, 5200H, 5500H, 5600H, VX8: before DKCMAIN Ver. 90-09-24-00/00, SVP Ver. 90-09-24/00, before DKCMAIN Ver. 90-08-86-00/00, SVP Ver. 90-08-86/00; Hitachi Virtual Storage Platform G1000, G1500, F1500, VX7: before DKCMAIN Ver. 80-06-96-00/00, SVP Ver. 80-06-91/00.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-06-29
Last Modified
2026-06-29
Generated
2026-06-29
AI Q&A
2026-06-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
hitachi virtual_storage_platform to 90-09-24-00/00 (exc)
hitachi virtual_storage_platform to 80-06-96-00/00 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-522 The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2025-7386 is an information exposure vulnerability in Hitachi Storage Navigator affecting multiple Hitachi Disk Array Systems when external authentication is used.

This flaw may expose authentication-related information but does not allow unauthorized access to the stored data itself.

The affected products include several models of Hitachi Virtual Storage Platform, such as G1000, G1500, F1500, 5100, 5200, 5500, 5600, and their H and VX series variants.

Impact Analysis

This vulnerability can lead to exposure of authentication-related information, which could potentially be used by attackers to gain insights into authentication mechanisms.

However, it does not allow attackers to access or modify the stored data directly.

The impact is primarily related to confidentiality of authentication information, which could increase the risk of further attacks if exploited.

Detection Guidance

There is no specific information provided about detection methods or commands to identify this vulnerability on your network or system.

Mitigation Strategies

To mitigate the vulnerability CVE-2025-7386 in Hitachi Storage Navigator, it is recommended to update the micro-program to the fixed versions.

  • Update to DKCMAIN Ver.80-06-96-00/00 with SVP Ver.80-06-91/00
  • Update to DKCMAIN Ver.90-08-86-00/00 with SVP Ver.90-08-86/00
  • Update to DKCMAIN Ver.90-09-24-00/00 with SVP Ver.90-09-24/00

Users should verify they are referencing the latest security advisory information due to potential updates.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-7386. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart