Back to overview

CVE-2024-2013

CRITICAL
10.0
CVSS 3.1
Description
An authentication bypass vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway component that if exploited allows attackers without any access to interact with the services and the post-authentication attack surface.

Metadata

CVE ID
CVE-2024-2013
State
PUBLISHED
Assigner
Hitachi Energy
Reserved
2024-02-29 13:42 UTC
Published
2024-06-11 13:14 UTC
Last updated
2024-08-01 18:56 UTC
Primary CWE
CWE-288
CWE-288 Authentication Bypass Using an Alternate Path or Cha…
Vendor / Product
Hitachi Energy / FOXMAN-UN
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
partial
Affected products (2)
VendorProductPlatformVersions
Hitachi Energy FOXMAN-UN FOXMAN-UN R16B PC2, FOXMAN-UN R16B PC3 ≤ FOXMAN-UN R16B PC4, FOXMAN-UN R15B PC4, FOXMAN-UN R15B PC5 …
Hitachi Energy UNEM UNEM R16B PC2, UNEM R16B PC3 ≤ UNEM R16B PC4, UNEM R15B PC4, UNEM R15B PC5 …
Weakness (CWE)
CWESourceDescription
CWE-288 cna CWE-288 Authentication Bypass Using an Alternate Path or Channel
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview