CVE-2024-28022
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/06/2024
Last modified:
29/04/2025
Description
A vulnerability exists in the UNEM server / APIGateway that if exploited allows a malicious user to perform an arbitrary number of<br />
authentication attempts using different passwords, and eventually<br />
gain access to other components in the same security realm using<br />
the targeted account.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:hitachienergy:foxman-un:r15a:*:*:*:*:*:*:* | ||
| cpe:2.3:a:hitachienergy:foxman-un:r15b:*:*:*:*:*:*:* | ||
| cpe:2.3:a:hitachienergy:foxman-un:r16a:*:*:*:*:*:*:* | ||
| cpe:2.3:a:hitachienergy:foxman-un:r16b:*:*:*:*:*:*:* | ||
| cpe:2.3:a:hitachienergy:unem:r15a:*:*:*:*:*:*:* | ||
| cpe:2.3:a:hitachienergy:unem:r15b:*:*:*:*:*:*:* | ||
| cpe:2.3:a:hitachienergy:unem:r16a:*:*:*:*:*:*:* | ||
| cpe:2.3:a:hitachienergy:unem:r16b:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://publisher.hitachienergy.com/preview?DocumentId=8DBD000194&languageCode=en&Preview=true
- https://publisher.hitachienergy.com/preview?DocumentId=8DBD000201&languageCode=en&Preview=true
- https://publisher.hitachienergy.com/preview?DocumentId=8DBD000194&languageCode=en&Preview=true
- https://publisher.hitachienergy.com/preview?DocumentId=8DBD000201&languageCode=en&Preview=true



