Improper Restriction of Excessive Authentication Attempts vulnerability in Hitachi Virtual Storage Platform
Summary
| CVE | CVE-2025-2514 |
|---|---|
| State | PUBLISHED |
| Assigner | Hitachi |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-05-07 09:16:26 UTC |
| Updated | 2026-05-13 19:14:56 UTC |
| Description | Improper restriction of excessive authentication attempts vulnerability in Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, Hitachi Virtual Storage Platform One Block 23, One Block 24, One Block 26, One Block 28. This issue affects Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, Hitachi Virtual Storage Platform One Block 23, One Block 24, One Block 26, One Block 28 : before DKCMAIN Ver 88-08-16-xx/00, GUM Ver. 88-08-20/00, before DKCMAIN Ver 93-07-26-xx/00, GUM Ver. 93-07-26/00, before DKCMAIN Ver A3-04-02-xx/00, EMS Ver. A3-04-02/00, before DKCMAIN Ver A3-03-41-xx/00, EMS Ver. A3-03-41/00, before DKCMAIN Ver A3-03-03-xx/00, EMS Ver. A3-03-02/00. |
Risk And Classification
Primary CVSS: v3.1 5.3 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS: 0.000420000 probability, percentile 0.128980000 (date 2026-05-21)
Problem Types: CWE-307 | CWE-307 CWE-307 Improper restriction of excessive authentication attempts
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
| 3.1 | CNA | CVSS | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
LowIntegrity
NoneAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Hitachi | Virtual Storage One Block | 23 | All | All | All |
| Application | Hitachi | Virtual Storage One Block | 24 | All | All | All |
| Application | Hitachi | Virtual Storage One Block | 26 | All | All | All |
| Application | Hitachi | Virtual Storage One Block | 28 | All | All | All |
| Hardware | Hitachi | Vsp E1090 | - | All | All | All |
| Hardware | Hitachi | Vsp E1090h | - | All | All | All |
| Operating System | Hitachi | Vsp E1090h Firmware | - | All | All | All |
| Operating System | Hitachi | Vsp E1090 Firmware | - | All | All | All |
| Hardware | Hitachi | Vsp E390 | - | All | All | All |
| Hardware | Hitachi | Vsp E390h | - | All | All | All |
| Operating System | Hitachi | Vsp E390h Firmware | - | All | All | All |
| Operating System | Hitachi | Vsp E390 Firmware | - | All | All | All |
| Hardware | Hitachi | Vsp E590 | - | All | All | All |
| Hardware | Hitachi | Vsp E590h | - | All | All | All |
| Operating System | Hitachi | Vsp E590h Firmware | - | All | All | All |
| Operating System | Hitachi | Vsp E590 Firmware | - | All | All | All |
| Hardware | Hitachi | Vsp E790 | - | All | All | All |
| Hardware | Hitachi | Vsp E790h | - | All | All | All |
| Operating System | Hitachi | Vsp E790h Firmware | - | All | All | All |
| Operating System | Hitachi | Vsp E790 Firmware | - | All | All | All |
| Hardware | Hitachi | Vsp E990 | - | All | All | All |
| Operating System | Hitachi | Vsp E990 Firmware | - | All | All | All |
| Hardware | Hitachi | Vsp F350 | - | All | All | All |
| Operating System | Hitachi | Vsp F350 Firmware | - | All | All | All |
| Hardware | Hitachi | Vsp F370 | - | All | All | All |
| Operating System | Hitachi | Vsp F370 Firmware | - | All | All | All |
| Hardware | Hitachi | Vsp F700 | - | All | All | All |
| Operating System | Hitachi | Vsp F700 Firmware | - | All | All | All |
| Hardware | Hitachi | Vsp F900 | - | All | All | All |
| Operating System | Hitachi | Vsp F900 Firmware | - | All | All | All |
| Hardware | Hitachi | Vsp G130 | - | All | All | All |
| Operating System | Hitachi | Vsp G130 Firmware | - | All | All | All |
| Hardware | Hitachi | Vsp G150 | - | All | All | All |
| Operating System | Hitachi | Vsp G150 Firmware | - | All | All | All |
| Hardware | Hitachi | Vsp G350 | - | All | All | All |
| Operating System | Hitachi | Vsp G350 Firmware | - | All | All | All |
| Hardware | Hitachi | Vsp G370 | - | All | All | All |
| Operating System | Hitachi | Vsp G370 Firmware | - | All | All | All |
| Hardware | Hitachi | Vsp G700 | - | All | All | All |
| Operating System | Hitachi | Vsp G700 Firmware | - | All | All | All |
| Hardware | Hitachi | Vsp G900 | - | All | All | All |
| Operating System | Hitachi | Vsp G900 Firmware | - | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.hitachi.com/products/it/storage-solutions/sec_info/2026/2026_306.html | [email protected] | www.hitachi.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.