CVE Vulnerabilities

CVE-2024-2012

Authentication Bypass Using an Alternate Path or Channel

Published: Jun 11, 2024 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway that if exploited an attacker could use to allow unintended commands or code to be executed on the UNEM server allowing sensitive data to be read or modified or could cause other unintended behavior

Weakness

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

NameVendorStart VersionEnd Version
Foxman-unHitachienergyr15a (including)r15a (including)
Foxman-unHitachienergyr15b-pc4 (including)r15b-pc4 (including)
Foxman-unHitachienergyr16a (including)r16a (including)
Foxman-unHitachienergyr16b-pc2 (including)r16b-pc2 (including)
UnemHitachienergyr15a (including)r15a (including)
UnemHitachienergyr15b-pc4 (including)r15b-pc4 (including)
UnemHitachienergyr15b-pc5 (including)r15b-pc5 (including)
UnemHitachienergyr16a (including)r16a (including)
UnemHitachienergyr16b-pc2 (including)r16b-pc2 (including)

Potential Mitigations

References