9.8

CVE-2024-2012

vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway that if exploited an attacker could use to allow unintended commands or 
code to be executed on the UNEM server allowing sensitive data to 
be read or modified or could cause other unintended behavior
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hitachienergy ≫ Foxman-un Version r15a
Hitachienergy ≫ Foxman-un Version r15b Update pc4
Hitachienergy ≫ Foxman-un Version r16a
Hitachienergy ≫ Foxman-un Version r16b Update pc2
Hitachienergy ≫ Unem Version r15a
Hitachienergy ≫ Unem Version r15b Update pc4
Hitachienergy ≫ Unem Version r15b Update pc5
Hitachienergy ≫ Unem Version r16a
Hitachienergy ≫ Unem Version r16b Update pc2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.6% 0.44
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cybersecurity@hitachienergy.com 9.1 2.3 6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CWE-288 Authentication Bypass Using an Alternate Path or Channel

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

https://publisher.hitachienergy.com/preview?DocumentId=8DBD000201&languageCode=en&Preview=true
Vendor Advisory