Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Hitachi, Ltd.

First CVE: Dec 1, 2003Active for: 23 yearsTotal CVEs: 217
47.8
VTI Score
High

Hitachi, Ltd. maintains a large and diverse portfolio of enterprise infrastructure, storage, and analytics products spanning device management, business intelligence platforms, middleware, and system tuning solutions—a footprint that reflects its role as a major supplier to large-scale IT deployments. Vulnerabilities affecting the vendor reach a meaningful share of serious severity across this broad product range, concentrating in web-facing and input-processing components where cross-site scripting, improper input validation, and permission misconfigurations recur. The exposure spans flagship products including Device Manager, Vantara Pentaho analytics platforms, UCOSMINEXUS middleware, and Tuning Manager, each representing integration points in enterprise infrastructure that can amplify the impact of underlying flaws. Defenders should prioritize inventory of Hitachi-supplied systems in critical roles and track the vendor's advisories for the infrastructure and analytics layers; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
217
Total CVEs
More Total CVEs than 100% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
6.5
Avg CVSS Score
Higher Avg CVSS Score than 41% of tracked vendors
0.9%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Hitachi, Ltd. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 1, 2003
22 years ago
Most Recent CVE
May 27, 2026
58 days ago

Self-Reporting Analysis

Of all the CVEs published by Hitachi, Ltd. as a CNA, 60.8% affect products that Hitachi, Ltd. develops as a vendor.

60.8%
39.2%
Self-reported: 45 (60.8%)
Third-party: 29 (39.2%)

Of all the CVEs published that affect products developed by Hitachi, Ltd., 20.7% are self-published by Hitachi, Ltd. as a CNA.

20.7%
79.3%
Self-published: 45 (20.7%)
Other CNAs: 172 (79.3%)

Products(278 total)

Top CVEs

Signals from CVEs in this vendor scope (217 CVEs).

217 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-43939CRITICAL
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonical URLs which can be circumven
Apr 3, 20239.899YESYES
CVE-2022-43769HIGH
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring temp
Apr 3, 20237.298YESYES
CVE-2005-0356MEDIUM
Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connect
May 31, 20055.069NOYES
CVE-2021-31602HIGH
An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. The Security Model has different layers of Access Control. One
Nov 8, 20217.564NOYES
CVE-2022-43938HIGH
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x cannot allow a system administrator to disable scripting capabilities of P
Apr 3, 20238.841NONO
CVE-2022-43773HIGH
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x is installed with a sample HSQLDB data source configured with stored proce
Apr 3, 20238.837NONO
CVE-2025-1978CRITICAL
Remote Code Execution Vulnerability in Hitachi Storage Navigator and the maintenance console in Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F70
May 7, 20269.836NONO
CVE-2025-9661CRITICAL
OS command injection vulneravility in the management gui (maintenance utility) of Hitachi Virtual Storage Platform One Block 23, 24, 26 and 28. This issue affects Hitachi Virtual
May 7, 20269.836NONO
CVE-2026-2253HIGH
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.7 and 11.0.0.0, including 9.3.x and 8.3.x, does not prevent certain XML parsers from resolving external
May 27, 20267.733NONO
CVE-2025-65115CRITICAL
Remote Code Execution Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - Operations Director on Windows, Job Management Partner 1/IT D
Apr 7, 20269.833NONO
View all 217 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products217 CVEs
56%
37%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local22 (10.1%)
Network95 (43.8%)
Unknown100 (46.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low112 (51.6%)
High5 (2.3%)
Unknown100 (46.1%)
User Interaction
None98 (45.2%)
Unknown100 (46.1%)
Required19 (8.8%)
Privileges Required
Low59 (27.2%)
High9 (4.1%)
None49 (22.6%)
Unknown100 (46.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (217 CVEs).

CISA KEV
2 CVEs
0.9% of CVEs· 99th percentile
Metasploit
2 CVEs
0.9% of CVEs· 97th percentile
Nuclei
3 CVEs
1.4% of CVEs· 95th percentile
ExploitDB
4 CVEs
1.8% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Hitachi, Ltd..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Hitachi, Ltd. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Hitachi, Ltd.'s Products

View all 7 CNAs →

Top CWEs