vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway that if exploited an attacker could use to allow unintended commands or code to be executed on the UNEM server allowing sensitive data to be read or modified or could cause other unintended behavior
The vulnerability results from improper access control or authentication (CWE-288) in the server layer or API Gateway of the FOXMAN-UN/UNEM system. An attacker with high-level privileges (PR:H) can trigger the execution of unintended commands or code on the UNEM server via the network (AV:N) without user interaction. The vulnerability operates in a context that extends beyond the boundaries of the attacked component's resources (S:C), indicating the possibility of impact on other elements of the environment.
An attacker can read or modify sensitive data stored on the UNEM server, execute unauthorized code, and cause other unintended system behavior, potentially affecting the availability, integrity, and confidentiality of the environment.
Apply patches available from the manufacturer according to the references (https://publisher.hitachienergy.com/preview?DocumentId=8DBD000201&languageCode=en&Preview=true). Additionally, it is recommended to restrict network access to the UNEM server and API Gateway only to trusted hosts and to apply the principle of least privilege.
Hitachi Energy products FOXMAN-UN and UNEM — versions indicated in the manufacturer's references
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HHitachienergy Foxman Un
APPHitachienergyr15ar15br16ar16bHitachienergy Unem
APPHitachienergyr15ar15br16ar16b
Related vulnerabilities
Authentication bypass w Hitachi Energy FOXMAN-UN/UNEM — pełny dostęp bez uwierzytelnienia
A vulnerability exists in the FOXMAN-UN/UNEM server that affects the message queueing mechanism’s certificate...
A heap-based buffer overflow vulnerability exists in the FOXMAN-UN/UNEM that if exploited will generally lead ...
A user/password reuse vulnerability exists in the FOXMAN-UN/UNEM application and server management. If exploit...
The affected products store both public and private key that are used to sign and protect Custom Parameter Se...