A vulnerability exists in the UNEM server / APIGateway that if exploited allows a malicious user to perform an arbitrary number of authentication attempts using different passwords, and eventually gain access to other components in the same security realm using the targeted account.
History

Tue, 29 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Oct 2024 14:45:00 +0000

Type Values Removed Values Added
Description A vulnerability exists in the FOXMAN-UN/UNEM server / APIGateway that if exploited allows a malicious user to perform an arbitrary number of authentication attempts using different passwords, and eventually gain access to the targeted account. A vulnerability exists in the UNEM server / APIGateway that if exploited allows a malicious user to perform an arbitrary number of authentication attempts using different passwords, and eventually gain access to other components in the same security realm using the targeted account.

Thu, 15 Aug 2024 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Hitachienergy
Hitachienergy foxman-un
Hitachienergy unem
CPEs cpe:2.3:a:hitachienergy:foxman-un:r15a:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:foxman-un:r15b:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:foxman-un:r16a:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:foxman-un:r16b:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:unem:r15a:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:unem:r15b:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:unem:r16a:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:unem:r16b:*:*:*:*:*:*:*
Vendors & Products Hitachienergy
Hitachienergy foxman-un
Hitachienergy unem

cve-icon MITRE

Status: PUBLISHED

Assigner: Hitachi Energy

Published: 2024-06-11T18:15:42.349Z

Updated: 2024-10-29T14:33:38.987Z

Reserved: 2024-02-29T13:42:00.746Z

Link: CVE-2024-28022

cve-icon Vulnrichment

Updated: 2024-08-02T00:48:47.751Z

cve-icon NVD

Status : Modified

Published: 2024-06-11T19:16:06.017

Modified: 2024-11-21T09:05:39.653

Link: CVE-2024-28022

cve-icon Redhat

No data.