CVE Vulnerabilities

CVE-2021-40341

Inadequate Encryption Strength

Published: Jan 05, 2023 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

DES cipher, which has inadequate encryption strength, is used Hitachi Energy FOXMAN-UN to encrypt user credentials used to access the Network Elements. Successful exploitation allows sensitive information to be decrypted easily. This issue affects 

  • FOXMAN-UN product: FOXMAN-UN R16A, FOXMAN-UN R15B, FOXMAN-UN R15A, FOXMAN-UN R14B, FOXMAN-UN R14A, FOXMAN-UN R11B, FOXMAN-UN R11A, FOXMAN-UN R10C, FOXMAN-UN R9C; 
  • UNEM product: UNEM R16A, UNEM R15B, UNEM R15A, UNEM R14B, UNEM R14A, UNEM R11B, UNEM R11A, UNEM R10C, UNEM R9C.

List of CPEs: 

  • cpe:2.3:a:hitachienergy:foxman-un:R16A:::::::*
  • cpe:2.3:a:hitachienergy:foxman-un:R15B:::::::*
  • cpe:2.3:a:hitachienergy:foxman-un:R15A:::::::*
  • cpe:2.3:a:hitachienergy:foxman-un:R14B:::::::*
  • cpe:2.3:a:hitachienergy:foxman-un:R14A:::::::*
  • cpe:2.3:a:hitachienergy:foxman-un:R11B:::::::*
  • cpe:2.3:a:hitachienergy:foxman-un:R11A:::::::*
  • cpe:2.3:a:hitachienergy:foxman-un:R10C:::::::*
  • cpe:2.3:a:hitachienergy:foxman-un:R9C:::::::*
  • cpe:2.3:a:hitachienergy:unem:R16A:::::::*
  • cpe:2.3:a:hitachienergy:unem:R15B:::::::*
  • cpe:2.3:a:hitachienergy:unem:R15A:::::::*
  • cpe:2.3:a:hitachienergy:unem:R14B:::::::*
  • cpe:2.3:a:hitachienergy:unem:R14A:::::::*
  • cpe:2.3:a:hitachienergy:unem:R11B:::::::*
  • cpe:2.3:a:hitachienergy:unem:R11A:::::::*
  • cpe:2.3:a:hitachienergy:unem:R10C:::::::*
  • cpe:2.3:a:hitachienergy:unem:R9C:::::::*

Weakness

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

Affected Software

NameVendorStart VersionEnd Version
Foxman-unHitachienergyr9c (including)r9c (including)
Foxman-unHitachienergyr10c (including)r10c (including)
Foxman-unHitachienergyr11a (including)r11a (including)
Foxman-unHitachienergyr11b (including)r11b (including)
Foxman-unHitachienergyr14a (including)r14a (including)
Foxman-unHitachienergyr14b (including)r14b (including)
Foxman-unHitachienergyr15a (including)r15a (including)
Foxman-unHitachienergyr15b (including)r15b (including)
Foxman-unHitachienergyr16a (including)r16a (including)
UnemHitachienergyr9c (including)r9c (including)
UnemHitachienergyr10c (including)r10c (including)
UnemHitachienergyr11a (including)r11a (including)
UnemHitachienergyr11b (including)r11b (including)
UnemHitachienergyr14a (including)r14a (including)
UnemHitachienergyr14b (including)r14b (including)
UnemHitachienergyr15a (including)r15a (including)
UnemHitachienergyr15b (including)r15b (including)
UnemHitachienergyr16a (including)r16a (including)

Potential Mitigations

References