Executive Summary
A critical deserialization of untrusted data vulnerability (CVE-2026-71374) has been identified in Cosminexus Component Container, a software component developed by Hitachi. This vulnerability affects multiple versions of the container across various platforms, including Windows, Linux, and AIX. With a CVSS score of 9.8, this vulnerability is considered highly severe and requires immediate attention.
Technical Analysis
The vulnerability is classified as a deserialization of untrusted data issue (CWE-502). It occurs when the Cosminexus Component Container improperly handles the deserialization of data, allowing an attacker to inject malicious data that can be executed by the container. The attack vector is network-based (AV:N), with low attack complexity (AC:L), and no privileges or user interaction required (PR:N/UI:N). The vulnerability affects the following versions of Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through 11-10-11, from 11-00 before 11-00-13, from 09-87 before 09-87-10, from 09-80 before 09-80-05, from 09-70 before 09-70-28, from 09-50 through 09-50-22, and from 09-00 through 09-00-18.
How It Gets Exploited
An unauthenticated remote attacker on the same network can exploit this vulnerability by sending a crafted, malicious payload to the Cosminexus Component Container. When the container attempts to deserialize this payload, the injected malicious data is executed, potentially allowing the attacker to achieve arbitrary code execution, data tampering, or other malicious activities. The attacker gains significant control over the affected system, including the ability to compromise confidentiality, integrity, and availability.
Impact Assessment
The impact of this vulnerability is significant, with a CVSS score of 9.8 indicating critical severity. Successful exploitation can lead to:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
The vulnerability affects a wide range of versions and platforms, increasing the blast radius. Hitachi has provided a detailed list of affected versions and recommended updates.
Recommended Actions
To mitigate this vulnerability, the following actions are recommended:
- Update Cosminexus Component Container to version 11-70-03 or later.
- Update Cosminexus Component Container to version 11-60-03 or later.
- Update Cosminexus Component Container to version 11-50-04 or later.
- Update Cosminexus Component Container to version 11-40-04 or later.
- Update Cosminexus Component Container to version 11-30-09 or later.
- Update Cosminexus Component Container to version 11-20-10 or later.
- Update Cosminexus Component Container to version 11-10-12 or later.
- Update Cosminexus Component Container to version 11-00-13 or later.
- Update Cosminexus Component Container to version 09-87-10 or later.
- Update Cosminexus Component Container to version 09-80-05 or later.
- Update Cosminexus Component Container to version 09-70-28 or later.
- For versions 09-50 and 09-00, apply the relevant patches or updates as recommended by Hitachi.
Detection guidance: Monitor system logs for unusual deserialization activities, and implement network segmentation to limit the attack surface.
Sources
- National Vulnerability Database (NVD)
- Hitachi Security Advisory