GPU VulnDB

Database/Firmware, BMC & network fabric

Hitachi VSP One Block: firmware update path does not validate the image before applying it

CVSS 3.7CVE-2025-0824Firmware, BMC & network fabriccurated

Impact

The storage array accepts a firmware update without adequate validation, so a low-privileged administrator who can drive the update flow - with an operator action to complete it - can get unverified code onto a controller that fronts shared datasets. On a fleet where the same array serves checkpoints and datasets to many GPU nodes, controller integrity is a blast-radius question: everything mounted from it is downstream. Hitachi scores this 3.7 because it needs authentication, user interaction and a high-complexity attack, and the record describes only limited integrity and availability impact. There is no evidence of remote unauthenticated exploitation.

Who can reach it

Network-reachable management interface of the array, requiring low-privilege authentication plus a legitimate operator completing the update. Anyone able to reach the storage management network is the relevant population - keep it off tenant-reachable paths.

What to do

Update to DKCMAIN A3-04-21-40/00 and ESM A3-04-21/00 or later per the Hitachi advisory. A controller firmware update on VSP One Block is a scheduled maintenance activity coordinated with Hitachi support; plan it as a firmware flash with the array in a degraded/one-controller-at-a-time state rather than an in-place restart.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.