Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Unrated

DoS Vulnerability in 10G iSCSI Interface of Hitachi Virtual Storage Platform

IdentifiersCVE-2025-7737CWE-400

CVE-2025-7737 is a remotely exploitable denial-of-service vulnerability affecting the 10G iSCSI interface in multiple Hitachi Virtual Storage Platform product families, including VSP E, G, F, VX, and 5000-series systems. The issue affects systems running firmware versions prior to the vendor-specified fixed DKCMAIN releases in combination with affected CHB(iSCSI) or ISFC firmware versions. The provided information does not identify the exact vulnerable function or parsing routine within the iSCSI implementation, but it indicates that the flaw resides in the 10G iSCSI interface and can be triggered over the network without privileges or user interaction.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation can cause a denial-of-service condition on the affected 10G iSCSI interface, impacting availability of storage services exposed through that interface. Based on the provided context, the primary consequence is disruption of iSCSI connectivity or service operation on impacted Hitachi Virtual Storage Platform systems; no evidence was provided for confidentiality, integrity, or code-execution impact.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching is not possible, reduce exposure of the 10G iSCSI interface to untrusted networks, restrict network access to authorized initiators and management domains only, and use segmentation or ACLs to limit who can reach the affected iSCSI service. Because the issue is remotely exploitable with no privileges or user interaction, minimizing reachable attack surface is the most relevant interim mitigation until firmware updates can be applied.

Remediation

Patch, then assume compromise.

Apply Hitachi's firmware updates for the affected platform and ensure both the controller firmware and the relevant interface firmware are updated to fixed versions. Specifically, upgrade DKCMAIN and the associated CHB(iSCSI) firmware, or ISFC firmware where applicable, to the vendor-recommended versions at or beyond the listed fixed releases for each affected product family.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
HitachiVirtual Storage Platform 5100hardware
HitachiVirtual Storage Platform 5100hhardware
HitachiVirtual Storage Platform 5200hardware
HitachiVirtual Storage Platform 5200hhardware
HitachiVirtual Storage Platform 5500hardware
HitachiVirtual Storage Platform 5500hhardware
HitachiVirtual Storage Platform 5600hardware
HitachiVirtual Storage Platform 5600hhardware
HitachiVirtual Storage Platform E1090hardware
HitachiVirtual Storage Platform E1090hhardware
HitachiVirtual Storage Platform E390hardware
HitachiVirtual Storage Platform E390hhardware
HitachiVirtual Storage Platform E590hardware
HitachiVirtual Storage Platform E590hhardware
HitachiVirtual Storage Platform E790hardware
HitachiVirtual Storage Platform E790hhardware
HitachiVirtual Storage Platform E990hardware
HitachiVirtual Storage Platform F1500hardware
HitachiVirtual Storage Platform F350hardware
HitachiVirtual Storage Platform F370hardware
HitachiVirtual Storage Platform F400hardware
HitachiVirtual Storage Platform F600hardware
HitachiVirtual Storage Platform F700hardware
HitachiVirtual Storage Platform F800hardware
HitachiVirtual Storage Platform F900hardware
HitachiVirtual Storage Platform G100hardware
HitachiVirtual Storage Platform G1000hardware
HitachiVirtual Storage Platform G130hardware
HitachiVirtual Storage Platform G150hardware
HitachiVirtual Storage Platform G1500hardware
HitachiVirtual Storage Platform G200hardware
HitachiVirtual Storage Platform G350hardware
HitachiVirtual Storage Platform G370hardware
HitachiVirtual Storage Platform G400hardware
HitachiVirtual Storage Platform G600hardware
HitachiVirtual Storage Platform G700hardware
HitachiVirtual Storage Platform G800hardware
HitachiVirtual Storage Platform G900hardware
HitachiVirtual Storage Platform Vx7hardware
HitachiVirtual Storage Platform Vx8hardware

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity5

Community discussion across Reddit, Mastodon, and other social sources.