We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-28022



Description

A vulnerability exists in the UNEM server / APIGateway that if exploited allows a malicious user to perform an arbitrary number of authentication attempts using different passwords, and eventually gain access to other components in the same security realm using the targeted account.

Reserved 2024-02-29 | Published 2024-06-11 | Updated 2024-10-29 | Assigner Hitachi Energy


MEDIUM: 6.5CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L

Problem types

CWE-307 Improper Restriction of Excessive Authentication Attempts

Product status

Default status
unaffected

FOXMAN-UN R16B
affected

FOXMAN-UN R15B
affected

FOXMAN-UN R16A
affected

FOXMAN-UN R15A
affected

Default status
unaffected

UNEM R16B
affected

UNEM R15B
affected

UNEM 16A
affected

UNEM 15A
affected

References

publisher.hitachienergy.com/...&languageCode=en&Preview=true

publisher.hitachienergy.com/...&languageCode=en&Preview=true

cve.org (CVE-2024-28022)

nvd.nist.gov (CVE-2024-28022)

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-28022

Support options

Helpdesk Chat, Email, Knowledgebase
Subscribe to our newsletter to learn more about our work.