Skip to content
Infrastructure

CVE-2025-2902

8.3
High
EPSS 0.35%Patch availableJun 29, 2026

Improper authorization of maintenance utility on Hitachi VSP.

common questions

Is CVE-2025-2902 being exploited?

Not confirmed. CVE-2025-2902 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.35% probability of exploitation in the next 30 days.

How severe is CVE-2025-2902?

CVE-2025-2902 is rated High with a CVSS score of 8.3. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.

Is there a patch for CVE-2025-2902?

Yes. A fix has been recorded for CVE-2025-2902. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.

What does CVE-2025-2902 affect?

CVE-2025-2902 affects Hitachi Virtual Storage Platform E390, Hitachi Virtual Storage Platform E590, Hitachi Virtual Storage Platform E790, Hitachi Virtual Storage Platform E990, and 23 further products or versions. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.

What should I do about CVE-2025-2902?

Apply latest firmware/maintenance patch addressing improper authorization.

Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.

executive summary
technical analysis
affected
Hitachi Virtual Storage Platform E390Hitachi Virtual Storage Platform E590Hitachi Virtual Storage Platform E790Hitachi Virtual Storage Platform E990Hitachi Virtual Storage Platform E1090Hitachi Virtual Storage Platform E390HHitachi Virtual Storage Platform E590HHitachi Virtual Storage Platform E790HHitachi Virtual Storage Platform E1090HHitachi Virtual Storage Platform 5100Hitachi Virtual Storage Platform 5100HHitachi Virtual Storage Platform 5500Hitachi Virtual Storage Platform 5500HHitachi Virtual Storage Platform 5200Hitachi Virtual Storage Platform 5600Hitachi Virtual Storage Platform 5200HHitachi Virtual Storage Platform 5600HHitachi Virtual Storage Platform G130Hitachi Virtual Storage Platform G150Hitachi Virtual Storage Platform G350Hitachi Virtual Storage Platform G370Hitachi Virtual Storage Platform G700Hitachi Virtual Storage Platform G900Hitachi Virtual Storage Platform F350Hitachi Virtual Storage Platform F370Hitachi Virtual Storage Platform F700Hitachi Virtual Storage Platform F900
impact

Unauthorized access to maintenance utilities could allow privileged actions affecting storage config, data integrity, or service availability.

action required

Patch when possible

affected versions
Hitachi Hitachi Virtual Storage Platform 5100, 5500, 5100H, 5500H, 5200, 5600, 5200H, 5600H
  • affected< DKCMAIN Ver. 90-09-27-00/00, GUM Ver. 90-09-27/00
Hitachi Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H
  • affected< DKCMAIN Ver. 93-07-26-xx/00, GUM Ver. 93-07-26/00
Hitachi Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900
  • affected< DKCMAIN Ver. 88-08-16-xx/00, GUM Ver. 88-08-20/00

As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.

how to fix
Remediation steps are tailored for users whose stack is affected. Add this technology to your stack to see the fix checklist.
references
get alerted

Track only the vulnerabilities that affect your infrastructure.

start for free