THREATINT

We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Fathom (Privacy friendly web analytics)
Zendesk (Helpdesk and Chat)

Ok

Home | EN
Support
CVE
PUBLISHED

CVE-2024-2013

AssignerHitachi Energy
Reserved2024-02-29
Published2024-06-11
Updated2024-06-12

Description

An authentication bypass vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway component that if exploited allows attackers without any access to interact with the services and the post-authentication attack surface.



CRITICAL: 10.0CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Problem types

CWE-288 Authentication Bypass Using an Alternate Path or Channel

Product status

Default status
unaffected

FOXMAN-UN R16B PC2
affected

FOXMAN-UN R16B PC3
unaffected

FOXMAN-UN R15B PC4
affected

FOXMAN-UN R15B PC5
unaffected

FOXMAN-UN R16A
affected

FOXMAN-UN R15A
affected

Default status
unaffected

UNEM R16B PC2
affected

UNEM R16B PC3
unaffected

UNEM R15B PC4
affected

UNEM R15B PC5
affected

UNEM R16B
affected

UNEM R15A
affected

References

https://publisher.hitachienergy.com/preview?DocumentId=8DBD000201&languageCode=en&Preview=true

cve.org CVE-2024-2013

nvd.nist.gov CVE-2024-2013

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-2013
© Copyright 2024 THREATINT. Made in Cyprus with +