March 12, 2026
Hitachi, Ltd. IT Products Management Division
Hitachi Disk Array Systems have the following vulnerabilities.
hitachi-sec-2026-303
A vulnerability exists in the SMI-S provider that is susceptible to XXE (XML External Entity) attacks.
CVE - CVE-2023-37364 (mitre.org)
The following table shows the affected products.
| Product Name |
Hitachi Virtual Storage Platform G1000, G1500, F1500 Hitachi Virtual Storage Platform 5100, 5500, 5100H, 5500H Hitachi Virtual Storage Platform 5200, 5600, 5200H, 5600H Hitachi Virtual Storage Platform G100, G200, G400, G600, G800 Hitachi Virtual Storage Platform F400, F600, F800 Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900 Hitachi Virtual Storage Platform F350, F370, F700, F900 Hitachi Virtual Storage Platform E590, E790, E990, E1090, E590H, E790H, E1090H |
|---|
The following table shows the modified micro-program version. Replace the micro-program with these versions.
| Micro-program Version |
DKCMAIN Ver. 80-06-93-00/81, SVP Ver. 80-06-88/80 DKCMAIN Ver. 90-09-20-00/01, SVP Ver. 90-09-20/01 DKCMAIN Ver. 90-09-01-00/80, SVP Ver. 90-09-01/80 DKCMAIN Ver. 90-08-83-00/80, SVP Ver. 90-08-83/80 DKCMAIN Ver. 90-08-63-00/80, SVP Ver. 90-08-64/80 DKCMAIN Ver. 83-06-20-X0/80, SVP Ver. 83-06-21-X0/80 DKCMAIN Ver. 83-05-48-X0/80, SVP Ver. 83-05-52-X0/80 DKCMAIN Ver. 88-08-10-X0/80, SVP Ver. 88-08-12-X0/80 DKCMAIN Ver. 93-07-20-X0/01, SVP Ver. 93-07-20-X0/01 DKCMAIN Ver. 93-07-01-X0/80, SVP Ver. 93-07-01-X0/80 DKCMAIN Ver. 93-06-82-X0/80, SVP Ver. 93-06-82-X0/80 DKCMAIN Ver. 93-06-63-X0/80, SVP Ver. 93-06-63-X0/80 |
|---|
Restrict access to the SMI-S provider via firewalls, etc., to allow access only from trusted IP addresses.
Additionally, if the SMI-S provider is not used with the following products, disabling the SMI-S provider can resolve the issue.
None