CVE-2026-71377

Summary

Command Argument Injection Vulnerability in Cosminexus Component Container.

This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through 11-10-11, from 11-00 through 11-00-12, from 09-87 before 09-87-10, from 09-80 through 09-80-04, from 09-70 before 09-70-28, from 09-50 through 09-50-22, and from 09-00 through 09-00-18.

Affected Software

VendorProductVersion RangeStatus
HitachiCosminexus Component Container11-70-01 < 11-70-03affected
HitachiCosminexus Component Container11-60 < 11-60-03affected
HitachiCosminexus Component Container11-50 <= 11-50-03affected
HitachiCosminexus Component Container11-40 <= 11-40-03affected
HitachiCosminexus Component Container11-30 <= 11-30-08affected
HitachiCosminexus Component Container11-20 < 11-20-10affected
HitachiCosminexus Component Container11-10 <= 11-10-11affected
HitachiCosminexus Component Container11-00 <= 11-00-12affected
HitachiCosminexus Component Container09-87 < 09-87-10affected
HitachiCosminexus Component Container09-80 <= 09-80-04affected
HitachiCosminexus Component Container09-70 < 09-70-28affected
HitachiCosminexus Component Container09-50 <= 09-50-22affected
HitachiCosminexus Component Container09-00 <= 09-00-18affected

Weaknesses

  • CWE-88: CWE-88 Improper neutralization of argument delimiters in a command ('argument injection')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: total

References