Intelligence View
⚡ tsecurity.de Intelligence
CVE-2025-0976 | Hitachi Ops Center API Configuration Manager log file (sec-2026-110 / EUVD-2025-208108)
A vulnerability, which was classified as problematic, has been found in Hitachi Ops Center API Configuration Manager and Configuration Manager. This impacts an…
A vulnerability, which was classified as problematic, has been found in Hitachi Ops Center API Configuration Manager and Configuration Manager. This impacts an unknown function. This manipulation causes sensitive information in log files.
The identification of this vulnerability is CVE-2025-0976. The attack can only be executed locally. There is no exploit available.
It is advisable to upgrade the affected component.
The identification of this vulnerability is CVE-2025-0976. The attack can only be executed locally. There is no exploit available.
It is advisable to upgrade the affected component.
Cyber Threat Intelligence & Forensik
ATT&CK-Navigator · IoC-Radar · Exploit-Belege
Compliance, SLA & Vendor Adherence
Advisory-Prüfung · Score-Einordnung · Fristen
CVSS 4.7CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Impact: 3.6 | Exploitability: 1.05
AVL
Lokal (Dateisystem / SSH)
Erfordert bereits ein lokales Benutzerkonto oder Ausführung vor Ort.
ACH
Hoch (High)
Erfordert Vorwissen, spezifische Zeitfenster oder unzuverlässige Race Conditions.
PRL
Niedrig (Standard-Benutzer)
Erfordert Anmeldedaten eines regulären Benutzers.
UIN
Keine (Zero-Click)
Autonom ohne menschliches Zutun ausführbar (Zero-Click Exploitation).
SU
Unverändert (Scope Unchanged)
Auswirkungen verbleiben isoliert in der angreifbaren Anwendungskomponente.
CH
Hoch (Totaler Abfluss)
Vollständiger Zugriff auf alle sensiblen Datenbank- und Speicherinhalte.
IN
Keine
Teilweise oder keine Manipulation.
AN
Keine
Teilweise oder keine Beeinträchtigung.
BSI-Warnung (Deutschland)CVE-2025-0976
Hitachi Configuration Manager: Schwachstelle ermöglicht Offenlegung von Informationen24.02.2026CISA-SSVC-Triage (vulnrichment)CVE-2025-0976
Exploitation: none (Keine bekannte Ausnutzung)Automatable: no (Nicht automatisierbar)Technical Impact: partial (Teilweise)
Quelle: CISA-ADP vulnrichment · Stand 2026-02-25T14:49:36.303623Z · CISA Coordinator
Advisory Radar
In herstellerseitiger Prüfung
Hersteller-Sicherheitsmeldungen & Patch-Status
Handlungsempfehlung für Administratoren
Hersteller-Advisory noch nicht formal hinterlegt. Regelmäßiges Re-Scanning der CTI-Quellen anberaumt.
Referenzen aus der Primärquelle („Verifiziert" nur bei Hersteller-Domäne):
-
Web Referencewww.hitachi.com