CVE-2025-2514

MEDIUM
Published May 7, 2026 Modified May 13, 2026 CWE-307

Description

Improper restriction of excessive authentication attempts vulnerability in Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, Hitachi Virtual Storage Platform One Block 23, One Block 24, One Block 26, One Block 28. This issue affects Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, Hitachi Virtual Storage Platform One Block 23, One Block 24, One Block 26, One Block 28  : before DKCMAIN Ver 88-08-16-xx/00, GUM Ver. 88-08-20/00, before DKCMAIN Ver 93-07-26-xx/00, GUM Ver. 93-07-26/00, before DKCMAIN Ver A3-04-02-xx/00, EMS Ver. A3-04-02/00, before DKCMAIN Ver A3-03-41-xx/00, EMS Ver. A3-03-41/00, before DKCMAIN Ver A3-03-03-xx/00, EMS Ver. A3-03-02/00.

CVSS v3.1 Score

5.3
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

EPSS — Exploit Prediction

0.0001
Probability of exploitation
0.03%
Percentile rank

EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.

Weakness Type (CWE)

CWE-307 CWE-307

Affected Products

Vendor Product
hitachi virtual_storage_one_block
hitachi virtual_storage_one_block
hitachi virtual_storage_one_block
hitachi virtual_storage_one_block
hitachi vsp_g130_firmware
hitachi vsp_g130
hitachi vsp_g150_firmware
hitachi vsp_g150
hitachi vsp_g350_firmware
hitachi vsp_g350
hitachi vsp_g370_firmware
hitachi vsp_g370
hitachi vsp_g700_firmware
hitachi vsp_g700
hitachi vsp_g900_firmware
hitachi vsp_g900
hitachi vsp_f350_firmware
hitachi vsp_f350
hitachi vsp_f370_firmware
hitachi vsp_f370
hitachi vsp_f700_firmware
hitachi vsp_f700
hitachi vsp_f900_firmware
hitachi vsp_f900
hitachi vsp_e390_firmware
hitachi vsp_e390
hitachi vsp_e590_firmware
hitachi vsp_e590
hitachi vsp_e790_firmware
hitachi vsp_e790
hitachi vsp_e990_firmware
hitachi vsp_e990
hitachi vsp_e1090_firmware
hitachi vsp_e1090
hitachi vsp_e390h_firmware
hitachi vsp_e390h
hitachi vsp_e590h_firmware
hitachi vsp_e590h
hitachi vsp_e790h_firmware
hitachi vsp_e790h
hitachi vsp_e1090h_firmware
hitachi vsp_e1090h

References

Frequently Asked Questions

What is CVE-2025-2514? +
Improper restriction of excessive authentication attempts vulnerability in Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, Hitachi Virtual Storage Platform One Block 23, One Block 24, One Block 26, One Block 28. This issue affects Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, Hitachi Virtual Storage Platform One Block 23, One Block 24, One Block 26, One Block 28  : before DKCMAIN Ver 88-08-16-xx/00, GUM Ver. 88-08-20/00, before DKCMAIN Ver 93-07-26-xx/00, GUM Ver. 93-07-26/00, before DKCMAIN Ver A3-04-02-xx/00, EMS Ver. A3-04-02/00, before DKCMAIN Ver A3-03-41-xx/00, EMS Ver. A3-03-41/00, before DKCMAIN Ver A3-03-03-xx/00, EMS Ver. A3-03-02/00. It has a CVSS v3.1 base score of 5.3 (MEDIUM).
How severe is CVE-2025-2514? +
CVE-2025-2514 has a CVSS v3.1 score of 5.3 out of 10, rated MEDIUM. This is a medium-severity vulnerability that should be remediated as part of regular maintenance. The EPSS score is 0.0001, placing it in the 0th percentile for exploitation probability.
What products are affected by CVE-2025-2514? +
CVE-2025-2514 affects products from hitachi, specifically: virtual_storage_one_block, vsp_e1090, vsp_e1090_firmware, vsp_e1090h, vsp_e1090h_firmware, vsp_e390, vsp_e390_firmware, vsp_e390h, vsp_e390h_firmware, vsp_e590, vsp_e590_firmware, vsp_e590h, vsp_e590h_firmware, vsp_e790, vsp_e790_firmware, vsp_e790h, vsp_e790h_firmware, vsp_e990, vsp_e990_firmware, vsp_f350, vsp_f350_firmware, vsp_f370, vsp_f370_firmware, vsp_f700, vsp_f700_firmware, vsp_f900, vsp_f900_firmware, vsp_g130, vsp_g130_firmware, vsp_g150, vsp_g150_firmware, vsp_g350, vsp_g350_firmware, vsp_g370, vsp_g370_firmware, vsp_g700, vsp_g700_firmware, vsp_g900, vsp_g900_firmware. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2025-2514? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2025-2514 — free, no signup required.

Start Free Scan