Database/Firmware, BMC & network fabric
Hitachi VSP One Block: firmware update path does not validate the image before applying it
Impact
The storage array accepts a firmware update without adequate validation, so a low-privileged administrator who can drive the update flow - with an operator action to complete it - can get unverified code onto a controller that fronts shared datasets. On a fleet where the same array serves checkpoints and datasets to many GPU nodes, controller integrity is a blast-radius question: everything mounted from it is downstream. Hitachi scores this 3.7 because it needs authentication, user interaction and a high-complexity attack, and the record describes only limited integrity and availability impact. There is no evidence of remote unauthenticated exploitation.
Who can reach it
Network-reachable management interface of the array, requiring low-privilege authentication plus a legitimate operator completing the update. Anyone able to reach the storage management network is the relevant population - keep it off tenant-reachable paths.
What to do
Update to DKCMAIN A3-04-21-40/00 and ESM A3-04-21/00 or later per the Hitachi advisory. A controller firmware update on VSP One Block is a scheduled maintenance activity coordinated with Hitachi support; plan it as a firmware flash with the array in a degraded/one-controller-at-a-time state rather than an in-place restart.
References
Related entries
- Arm C1-Pro before r1p2; Trusted Firmware-A v2.10 and later on multi-core configurations with the CME complex enabledCVE-2026-0995 · Arm C1-Pro before r1p2; Trusted Firmware-A v2.10 and later on multi-core configurations with the CME complex enabledLow
- EDK II NetworkPkg (IScsiDxe, Ready-To-Transfer PDU handling): A malicious iSCSI target sends a crafted R2T PDUCVE-2025-2295 · EDK II NetworkPkg (IScsiDxe, Ready-To-Transfer PDU handling)Low
- Dell iDRAC9 / iDRAC10 (memory erase, data remanence): Data survives an iDRAC memory erase and stays readableCVE-2026-70412 · Dell iDRAC9 / iDRAC10 (memory erase, data remanence)Low
- AMD SEV guest VMs - TLB flush after VMCB creation sequence: The CPU may fail to flush the TLB after a particularCVE-2021-26342 · AMD SEV guest VMs - TLB flush after VMCB creation sequenceLow
- AMD SEV-SNP guest context page - use-after-free enabling migration-agent masquerade (AMD-SB-3002): A use-after-free inCVE-2023-20519 · AMD SEV-SNP guest context page - use-after-free enabling migration-agent masquerade (AMD-SB-3002)Low
- Intel TDX firmware (PRNG seeding): A predictable seed in the TDX firmware's pseudo-random number generator. PredictableCVE-2025-20613 · Intel TDX firmware (PRNG seeding)Low
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.