CVE-2025-2902Disclosure

LOWCVSS 8.3 · HIGH

Signal is active with 6 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform. This issue affects Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H: before DKCMAIN Ver. 93-07-26-xx/00, GUM Ver. 93-07-26/00; Hitachi Virtual Storage Platform 5100, 5500, 5100H, 5500H, 5200, 5600, 5200H, 5600H: before DKCMAIN Ver. 90-09-27-00/00, GUM Ver. 90-09-27/00; Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900: before DKCMAIN Ver. 88-08-16-xx/00, GUM Ver. 88-08-20/00.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • 6 total mentions across 1 day

Deep dive

Activity timeline6 mentions / 1d
02356Mentions · 2026-06-29: 6Patch / Workaround · 2026-06-29: 1Technical Details · 2026-06-29: 506-29
Signal classification2 categories
Disclosure
583.3%
Patch
116.7%
Referenced assets4 URLs
Full discourse6 posts
  • YogSotho@YogSoth0
    Disclosure

    #CVE-2025-2902 #Hitachi Virtual Storage Platform #Exploit Kit ## Overview Improper Authorization Vulnerability in Hitachi Virtual Storage Platform Maintenance Utility. ## Affected targets: This vulnerability affects multiple Hitachi #VSP series: - **E-series**: E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H (DKCMAIN < 93-07-26) - **5xxx-series**: 5100, 5500, 5100H, 5500H, 5200, 5600, 5200H, 5600H (DKCMAIN < 90-09-27) - **G/F-series**: G130, G150, G350, G370, G700, G900, F350, F370, F700, F900 (DKCMAIN < 88-08-16) #0days #cybersecurity #security #hacking #infosec #antisec

    Post summary

    The post announces an improper authorization flaw in Hitachi Virtual Storage Platform maintenance utilities, detailing affected models but offering no exploits, patches, or mitigation strategies.

    1201241.1K
    1.9K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-2902 Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform. This issue affects Hitachi Virtual Storage Platform E390, E590, E790, … https://www.cve.org/CVERecord?id=CVE-2025-2902

    Post summary

    The post announces CVE-2025-2902 as an improper authorization flaw in Hitachi Virtual Storage Platform models, providing no further technical or remediation details.

    00010827
    57.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-2902 Improper Authorization Vulnerability in Hitachi Virtual Storage Platform Maintenance Utility https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-2902

    Post summary

    A brief disclosure notes an improper‑authorization vulnerability in Hitachi’s Virtual Storage Platform, but no exploitation evidence, PoC, or patch information is provided.

    00010105
    4.1K followersView on X
  • ADK Cyber@ADKCyber
    Disclosure

    Hitachi Virtual Storage Platform users: CVE-2025-2902 (CVSS 8.3) is a high-severity improper authorization flaw affecting E390/E590/E790/E990/E1090 and H models. Review: https://nvd.nist.gov/vuln/deta… via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability https://t.co/zT6YbBbYdq

    Post summary

    The tweet announces a new high‑severity improper authorization flaw (CVE‑2025‑2902) affecting multiple Hitachi Virtual Storage Platform models and points to the NVD for more details.

    0000042
    92 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-2902 Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform. This issue affects Hitachi Virtual Storage Platform E390, E590, E790, … https://www.cve.org/CVERecord?id=CVE-2025-2902 ----- Traducción: CVE-2025-2902 Vul… http://infoflow.cloud`

    Post summary

    The text announces CVE-2025-2902, an Improper Authorization vulnerability affecting Hitachi Virtual Storage Platform, and links to the official CVE record, providing no PoC, exploit code, or remediation details.

    0000025
    89 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH SEVERITY: CVE-2025-2902 (CVSS 8.3) Improper authorization flaw in Hitachi Virtual Storage Platform maintenance utility. Network-exploitable, low complexity. Affects: VSP E/G/F series &amp; 5000 series Patch immediately to latest DKCMAIN/GUM versions. https://t.co/yIqB8Eey4d

    Post summary

    The post reports a high‑severity (CVSS 8.3) improper authorization flaw in Hitachi Virtual Storage Platform's maintenance utility and advises patching to the latest DKCMAIN/GUM versions immediately.

    0000039
    52 followersView on X

Explore more