9.8

CVE-2024-2012

vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway that if exploited an attacker could use to allow unintended commands or 
code to be executed on the UNEM server allowing sensitive data to 
be read or modified or could cause other unintended behavior
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HitachienergyFoxman-un Versionr15a
HitachienergyFoxman-un Versionr15b Updatepc4
HitachienergyFoxman-un Versionr16a
HitachienergyFoxman-un Versionr16b Updatepc2
HitachienergyUnem Versionr15a
HitachienergyUnem Versionr15b Updatepc4
HitachienergyUnem Versionr15b Updatepc5
HitachienergyUnem Versionr16a
HitachienergyUnem Versionr16b Updatepc2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.31% 0.534
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cybersecurity@hitachienergy.com 9.1 2.3 6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CWE-288 Authentication Bypass Using an Alternate Path or Channel

The product requires authentication, but the product has an alternate path or channel that does not require authentication.