Missing Password Masking in Hitachi Infrastructure Analytics Advisor, Hitachi Ops Center Analyzer and Hitachi Ops Center Analyzer viewpoint
Summary
| CVE | CVE-2026-3314 |
|---|---|
| State | PUBLISHED |
| Assigner | Hitachi |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-05-26 07:16:18 UTC |
| Updated | 2026-05-26 20:03:50 UTC |
| Description | Missing password field masking vulnerability in Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view, Hitachi Ops Center Analyzer probe modules), Hitachi Ops Center Analyzer viewpoint, Hitachi Infrastructure Analytics Advisor (Data Center Analytics, Analytics probe modules). This issue affects Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.8-00; Hitachi Ops Center Analyzer viewpoint: from 10.8.1-00 before 11.0.8-00; Hitachi Infrastructure Analytics Advisor: from 3.2.0-00 before 11.0.8-00. |
Risk And Classification
Primary CVSS: v3.1 4.6 MEDIUM from [email protected]
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS: 0.000160000 probability, percentile 0.038700000 (date 2026-05-31)
Problem Types: CWE-549 | CWE-549 CWE-549 Missing password field masking
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 4.6 | MEDIUM | CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| 3.1 | CNA | CVSS | 4.6 | MEDIUM | CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
CVSS v3.1 Breakdown
Attack Vector
PhysicalAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
NoneAvailability
NoneCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Hitachi | Hitachi Ops Center Analyzer | affected 10.0.0-00 11.0.8-00 custom | Linux, 64 bit |
| CNA | Hitachi | Hitachi Ops Center Analyzer Viewpoint | affected 10.8.1-00 11.0.8-00 custom | Linux, 64 bit |
| CNA | Hitachi | Hitachi Infrastructure Analytics Advisor | affected 3.2.0-00 11.0.8-00 custom | Linux, 64 bit |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.hitachi.com/products/it/software/security/info/vuls/hitachi-sec-2026-120/... | [email protected] | www.hitachi.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.