4.4

CVE-2023-1711

A vulnerability exists in a FOXMAN-UN and UNEM logging component, it only affects systems that use remote authentication to the network elements. 
If exploited an attacker could obtain confidential information.



List of CPEs:
  *  cpe:2.3:a:hitachienergy:foxman_un:R9C:*:*:*:*:*:*:*
  *  cpe:2.3:a:hitachienergy:foxman_un:R10C:*:*:*:*:*:*:*

  *  cpe:2.3:a:hitachienergy:foxman_un:R11A:*:*:*:*:*:*:*

  *  cpe:2.3:a:hitachienergy:foxman_un:R11B:*:*:*:*:*:*:*

  *  cpe:2.3:a:hitachienergy:foxman_un:R14A:*:*:*:*:*:*:*

  *  cpe:2.3:a:hitachienergy:foxman_un:R14B:*:*:*:*:*:*:*

  *  cpe:2.3:a:hitachienergy:foxman_un:R15A:*:*:*:*:*:*:*

  *  cpe:2.3:a:hitachienergy:foxman_un:R15B:*:*:*:*:*:*:*

  *  cpe:2.3:a:hitachienergy:foxman_un:R16A:*:*:*:*:*:*:*

  *  
  *  cpe:2.3:a:hitachienergy:unem:R9C:*:*:*:*:*:*:*
  *  cpe:2.3:a:hitachienergy: unem :R10C:*:*:*:*:*:*:*

  *  cpe:2.3:a:hitachienergy: unem :R11A:*:*:*:*:*:*:*

  *  cpe:2.3:a:hitachienergy: unem :R11B:*:*:*:*:*:*:*

  *  cpe:2.3:a:hitachienergy: unem :R14A:*:*:*:*:*:*:*

  *  cpe:2.3:a:hitachienergy: unem :R14B:*:*:*:*:*:*:*

  *  cpe:2.3:a:hitachienergy: unem :R15A:*:*:*:*:*:*:*

  *  cpe:2.3:a:hitachienergy: unem :R15B:*:*:*:*:*:*:*

  *  cpe:2.3:a:hitachienergy: unem :R16A:*:*:*:*:*:*:*


Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HitachienergyFoxman-un Versionr9c
HitachienergyFoxman-un Versionr10c
HitachienergyFoxman-un Versionr11a
HitachienergyFoxman-un Versionr11b
HitachienergyFoxman-un Versionr14a
HitachienergyFoxman-un Versionr14b
HitachienergyFoxman-un Versionr15a
HitachienergyFoxman-un Versionr15b
HitachienergyFoxman-un Versionr16a
HitachienergyUnem Versionr9c
HitachienergyUnem Versionr10c
HitachienergyUnem Versionr11a
HitachienergyUnem Versionr11b
HitachienergyUnem Versionr14a
HitachienergyUnem Versionr14b
HitachienergyUnem Versionr15a
HitachienergyUnem Versionr15b
HitachienergyUnem Versionr16a
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.1% 0.283
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.4 0.8 3.6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
cybersecurity@hitachienergy.com 4 0.3 3.6
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N
CWE-116 Improper Encoding or Escaping of Output

The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

CWE-117 Improper Output Neutralization for Logs

The product does not neutralize or incorrectly neutralizes output that is written to logs.