Communication between the client and the server application of the affected products is partially done using CORBA (Common Object Request Broker Architecture) over TCP/IP. This protocol is not encrypted and allows tracing of internal messages.
This issue affects
List of CPEs:
cpe:2.3:a:hitachienergy:foxman-un:R15B:::::::*
cpe:2.3:a:hitachienergy:foxman-un:R15A:::::::*
cpe:2.3:a:hitachienergy:foxman-un:R14B:::::::*
cpe:2.3:a:hitachienergy:foxman-un:R14A:::::::*
cpe:2.3:a:hitachienergy:foxman-un:R11B:::::::*
cpe:2.3:a:hitachienergy:foxman-un:R11A:::::::*
cpe:2.3:a:hitachienergy:foxman-un:R10C:::::::*
cpe:2.3:a:hitachienergy:foxman-un:R9C:::::::*
cpe:2.3:a:hitachienergy:unem:R15B:::::::*
cpe:2.3:a:hitachienergy:unem:R15A:::::::*
cpe:2.3:a:hitachienergy:unem:R14B:::::::*
cpe:2.3:a:hitachienergy:unem:R14A:::::::*
cpe:2.3:a:hitachienergy:unem:R11B:::::::*
cpe:2.3:a:hitachienergy:unem:R11A:::::::*
cpe:2.3:a:hitachienergy:unem:R10C:::::::*
cpe:2.3:a:hitachienergy:unem:R9C:::::::*
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Foxman-un | Hitachienergy | * | r16a (excluding) |
Unem | Hitachienergy | * | r16a (excluding) |