CVE-2026-71374
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Summary
Deserialization of untrusted data vulnerability in Cosminexus Component Container.
This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through 11-10-11, from 11-00 before 11-00-13, from 09-87 before 09-87-10, from 09-80 before 09-80-05, from 09-70 before 09-70-28, from 09-50 through 09-50-22, and from 09-00 through 09-00-18.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Hitachi | Cosminexus Component Container | 11-70-01 < 11-70-03 | affected |
| Hitachi | Cosminexus Component Container | 11-60 < 11-60-03 | affected |
| Hitachi | Cosminexus Component Container | 11-50 <= 11-50-03 | affected |
| Hitachi | Cosminexus Component Container | 11-40 <= 11-40-03 | affected |
| Hitachi | Cosminexus Component Container | 11-30 <= 11-30-08 | affected |
| Hitachi | Cosminexus Component Container | 11-20 < 11-20-10 | affected |
| Hitachi | Cosminexus Component Container | 11-10 <= 11-10-11 | affected |
| Hitachi | Cosminexus Component Container | 11-00 < 11-00-13 | affected |
| Hitachi | Cosminexus Component Container | 09-87 < 09-87-10 | affected |
| Hitachi | Cosminexus Component Container | 09-80 < 09-80-05 | affected |
| Hitachi | Cosminexus Component Container | 09-70 < 09-70-28 | affected |
| Hitachi | Cosminexus Component Container | 09-50 <= 09-50-22 | affected |
| Hitachi | Cosminexus Component Container | 09-00 <= 09-00-18 | affected |
Weaknesses
- CWE-502: CWE-502 Deserialization of untrusted data
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: yes
- Technical Impact: total
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.