{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2025-0824", "assignerOrgId": "50d0f415-c707-4733-9afc-8f6c0e9b3f82", "state": "PUBLISHED", "assignerShortName": "Hitachi", "dateReserved": "2025-01-29T07:25:51.664Z", "datePublished": "2026-06-29T05:34:34.668Z", "dateUpdated": "2026-06-29T12:38:48.701Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "50d0f415-c707-4733-9afc-8f6c0e9b3f82", "shortName": "Hitachi", "dateUpdated": "2026-06-29T05:34:34.668Z" }, "title": "lack of validation for firmware update in Hitachi Virtual Storage", "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-347", "description": "CWE-347 Improper verification of cryptographic signature", "type": "CWE" } ] } ], "impacts": [ { "capecId": "CAPEC-473", "descriptions": [ { "lang": "en", "value": "CAPEC-473 Signature Spoof" } ] } ], "affected": [ { "vendor": "Hitachi", "product": "Hitachi Virtual Storage Platform One Block 23, 24, 26, 28", "versions": [ { "status": "affected", "version": "0", "lessThan": "DKCMAIN A3-04-21-40/00, ESM A3-04-21/00", "changes": [ { "at": "DKCMAIN A3-04-21-40/00, ESM A3-04-21/00", "status": "unaffected" } ], "versionType": "custom" } ], "defaultStatus": "unaffected" } ], "descriptions": [ { "lang": "en", "value": "Lack of validation for firmware update in Hitachi Hitachi Virtual Storage Platform One Block 23, 24, 26, 28.\n\nThis issue affects Hitachi Virtual Storage Platform One Block 23, 24, 26, 28: before DKCMAIN A3-04-21-40/00, ESM A3-04-21/00.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "Lack of validation for firmware update in Hitachi Hitachi Virtual Storage Platform One Block 23, 24, 26, 28.

This issue affects Hitachi Virtual Storage Platform One Block 23, 24, 26, 28: before DKCMAIN A3-04-21-40/00, ESM A3-04-21/00.

" } ] } ], "references": [ { "url": "https://www.hitachi.com/products/it/storage-solutions/sec_info/2026/2026_308.html", "tags": [ "vendor-advisory" ] } ], "metrics": [ { "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ], "cvssV3_1": { "version": "3.1", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "availabilityImpact": "LOW", "baseSeverity": "LOW", "baseScore": 3.7, "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:L" } } ], "source": { "advisory": "hitachi-sec-2026-308", "discovery": "UNKNOWN" }, "x_generator": { "engine": "Vulnogram 1.0.2" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-06-29T12:38:22.989556Z", "id": "CVE-2025-0824", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-06-29T12:38:48.701Z" } } ] } }