Cyber Resilience

CVE-2025-1978

High

Published: 07 May 2026

Published
07 May 2026
Modified
13 May 2026
KEV Added
Patch
CVSS Score v3.1 8.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
EPSS Score 0.0055 41.8th percentile
Risk Priority 55 floored blend · peak EPSS

Summary

CVE-2025-1978 is a high-severity Code Injection (CWE-94) vulnerability in Hitachi Virtual Storage One Block. Its CVSS base score is 8.3 (High).

Operationally, ranked at the 41.8th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

OWASP Top 10 for Web (2025)

EU & UK References

Vulnerability details

Remote Code Execution Vulnerability in Hitachi Storage Navigator and the maintenance console in Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H,…

more

Hitachi Virtual Storage Platform One Block 23, One Block 24, One Block 26, One Block 28. This issue affects Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, Hitachi Virtual Storage Platform One Block 23, One Block 24, One Block 26, One Block 28 : before DKCMAIN Ver. 88-08-16-xx/00, SVP Ver. 88-08-18-xx/00, before DKCMAIN Ver. 93-07-26-xx/00, SVP Ver. 93-07-26-xx/00, before DKCMAIN Ver. A3-04-02-xx/00, MPC Ver. A3-04-02-xx/00, before DKCMAIN Ver. A3-03-41-xx/00, MPC Ver. A3-03-41-xx/00, before DKCMAIN Ver. A3-03-03-xx/00, MPC Ver. A3-03-03-xx/00.

CWE(s)

Related Threats

CVEs Like This One

CVE-2025-9661Same product: Hitachi Virtual Storage One Block
CVE-2025-11159Same vendor: Hitachi
CVE-2025-11158Same vendor: Hitachi
CVE-2021-47939Shared CWE-94
CVE-2026-41229Shared CWE-94
CVE-2026-44262Shared CWE-94
CVE-2026-26045Shared CWE-94
CVE-2025-33239Shared CWE-94
CVE-2024-11600Shared CWE-94
CVE-2025-41717Shared CWE-94

Affected Assets

hitachi
virtual storage one block
23, 24, 26, 28
hitachi
vsp g130 firmware
all versions
hitachi
vsp g150 firmware
all versions
hitachi
vsp g350 firmware
all versions
hitachi
vsp g370 firmware
all versions
hitachi
vsp g700 firmware
all versions
hitachi
vsp g900 firmware
all versions
hitachi
vsp f350 firmware
all versions
hitachi
vsp f370 firmware
all versions
hitachi
vsp f700 firmware
all versions
+10 more product configuration(s) — see NVD for full list

Mitigating Controls

Likely Mitigating Controls AI

Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.

addresses: CWE-94

Makes persistent code injection into loaded programs impossible when the executable image itself resides on hardware-protected read-only media.

addresses: CWE-94

Dynamically generated code can be produced and executed inside the isolated chamber, preventing host compromise from code-injection payloads.

addresses: CWE-94

Validates inputs used in dynamic code generation to block injected directives.

addresses: CWE-94

Directly prevents execution of attacker-supplied code written into data memory regions.

References