10

CVE-2024-2013

An authentication bypass vulnerability exists in the FOXMAN-UN/UNEM server /
API Gateway component that if exploited allows attackers without 
any access to interact with the services and the post-authentication 
attack surface.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HitachienergyFoxman-un Versionr15a
HitachienergyFoxman-un Versionr15b Updatepc4
HitachienergyFoxman-un Versionr16a
HitachienergyFoxman-un Versionr16b Updatepc2
HitachienergyUnem Versionr15a
HitachienergyUnem Versionr15b Updatepc4
HitachienergyUnem Versionr15b Updatepc5
HitachienergyUnem Versionr16b
HitachienergyUnem Versionr16b Updatepc2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.09% 0.252
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 10 3.9 6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
cybersecurity@hitachienergy.com 10 3.9 6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-288 Authentication Bypass Using an Alternate Path or Channel

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

CWE-306 Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.