CVE-2025-0976
Published: 25 February 2026
Summary
CVE-2025-0976 is a medium-severity Insertion of Sensitive Information into Log File (CWE-532) vulnerability in Hitachi Configuration Manager. Its CVSS base score is 4.7 (Medium).
Operationally, exploitation aligns with the MITRE ATT&CK technique Data from Local System (T1005); ranked at the 11.6th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
Threat & Defense at a Glance
Threat & Defense Details
Likely Mitigating ControlsAI
Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.
Procedures mandate excluding sensitive data from logs to prevent unauthorized exposure via audit records.
Identifies insertion of sensitive data into logs, allowing detection of unauthorized disclosure.
Cross-organizational coordination enables agreement on what data to include in audit logs, directly reducing insertion of sensitive information.
Identifying logging as a data action allows prevention of sensitive information being inserted into log files.
The process of identifying and eradicating spilled information applies directly to sensitive data inserted into log files.
Specific processing rules for sensitive PII categories commonly include restrictions on logging, making insertion of such data into log files less likely.
PIAs detect planned or existing logging of PII and require removal or protection, preventing insertion of sensitive information into logs.
Limits insertion of sensitive operational details into logs by treating such data as key information requiring protection.
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
Local information exposure vulnerability (CWE-532) directly enables collection of sensitive data from system files/logs.
NVD Description
Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager.This issue affects Hitachi Ops Center API Configuration Manager: from 10.0.0-00 before 11.0.4-00; Hitachi Configuration Manager: from 8.6.1-00 before 11.0.5-00.
Deeper analysisAI
CVE-2025-0976 is an information exposure vulnerability (CWE-532) in Hitachi Ops Center API Configuration Manager and Hitachi Configuration Manager. It affects Hitachi Ops Center API Configuration Manager versions from 10.0.0-00 before 11.0.4-00 and Hitachi Configuration Manager versions from 8.6.1-00 before 11.0.5-00. The vulnerability was published on 2026-02-25T05:17:13.900 and carries a CVSS v3.1 base score of 4.7 (Medium: AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).
Exploitation requires a local attacker with low privileges to perform actions under high attack complexity, with no user interaction needed and no scope change. Successful attacks result in high confidentiality impact through exposure of sensitive information, with no impact on integrity or availability.
The Hitachi security advisory (https://www.hitachi.com/products/it/software/security/info/vuls/hitachi-sec-2026-110/index.html) details the issue. Mitigation requires upgrading to Hitachi Ops Center API Configuration Manager 11.0.4-00 or later and Hitachi Configuration Manager 11.0.5-00 or later.
Details
- CWE(s)