CRITICAL🇵🇱 Wersja polska

CVE-2024-2012

CVSS 9.1v3.1pub. 2024-06-11upd. 2024-11-21

vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway that if exploited an attacker could use to allow unintended commands or code to be executed on the UNEM server allowing sensitive data to be read or modified or could cause other unintended behavior

🤖 AI Analysis
How it works

The vulnerability results from improper access control or authentication (CWE-288) in the server layer or API Gateway of the FOXMAN-UN/UNEM system. An attacker with high-level privileges (PR:H) can trigger the execution of unintended commands or code on the UNEM server via the network (AV:N) without user interaction. The vulnerability operates in a context that extends beyond the boundaries of the attacked component's resources (S:C), indicating the possibility of impact on other elements of the environment.

Impact

An attacker can read or modify sensitive data stored on the UNEM server, execute unauthorized code, and cause other unintended system behavior, potentially affecting the availability, integrity, and confidentiality of the environment.

Mitigation & patch

Apply patches available from the manufacturer according to the references (https://publisher.hitachienergy.com/preview?DocumentId=8DBD000201&languageCode=en&Preview=true). Additionally, it is recommended to restrict network access to the UNEM server and API Gateway only to trusted hosts and to apply the principle of least privilege.

Who is affected

Hitachi Energy products FOXMAN-UN and UNEM — versions indicated in the manufacturer's references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Hitachienergy Foxman Un

    APP
    Hitachienergy
    r15ar15br16ar16b
  • Hitachienergy Unem

    APP
    Hitachienergy
    r15ar15br16ar16b
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-2013CRITICAL10.0PL ✓same product

Authentication bypass w Hitachi Energy FOXMAN-UN/UNEM — pełny dostęp bez uwierzytelnienia

CVE-2024-28021HIGH7.4same product

A vulnerability exists in the FOXMAN-UN/UNEM server that affects the message queueing mechanism’s certificate...

CVE-2024-2011HIGH8.6same product

A heap-based buffer overflow vulnerability exists in the FOXMAN-UN/UNEM that if exploited will generally lead ...

CVE-2024-28020HIGH8.0same product

A user/password reuse vulnerability exists in the FOXMAN-UN/UNEM application and server management. If exploit...

CVE-2022-3927HIGH8.0same product

The affected products store both public and private key that are used to sign and protect Custom Parameter Se...