Back to Database
Status published
High
CVE-2022-4441
Privilege Escalation Vulnerability in Hitachi Storage Plug-in for VMware vCenter
Vulnerability Description
Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMware vCenter allows remote authenticated users to cause privilege escalation. This issue affects Hitachi Storage Plug-in for VMware vCenter: from 04.9.0 before 04.9.1.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-4441
Credits & Attribution
No credits recorded in the NVD database.
References
More from Hitachi
View All →CVE-2025-9661
OS command injection vulneravility in the management gui (maintenance utility) of Hitachi Virtual Storage Platform One Block 23/24/26/28
High
8.1
CVE-2025-7737
DoS Vulnerability in 10G iSCSI Interface of Hitachi Virtual Storage Platform
High
8.6
CVE-2025-7386
Information exposure vulnerability in Hitachi Storage Navigator
Medium
6.8
CVE-2025-66445
Authorization bypass vulnerability in Hitachi Infrastructure Analytics Advisor and Hitachi Ops Center Analyzer
High
7.1
CVE-2025-66444
Cross-Site Scripting vulnerability in Hitachi Infrastructure Analytics Advisor and Hitachi Ops Center Analyzer
High
8.2
Affected Vendor
Hitachi
View all reports →Affected Software
Hitachi Storage Plug-in for VMware vCenter
Vulnerable Versions:
04.9.0
Timeline
Official Publish:
January 31st, 2023
Last Modified:
March 26th, 2025
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
MITRE ATT&CK TTPs
T1078
Valid Accounts
Persistence
T1098
Account Manipulation
Privilege Escalation
T1548
Abuse Elevation Control Mechanism
Privilege Escalation
T1484
Domain or Tenant Policy Modification
Defense Evasion
T1021
Remote Services
Lateral Movement
T1190
Exploit Public-Facing Application
Initial Access
T1556
Modify Authentication Process
Credential Access