CVE Vulnerabilities

CVE-2024-2012

Authentication Bypass Using an Alternate Path or Channel

Published: Jun 11, 2024 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway that if exploited an attacker could use to allow unintended commands or code to be executed on the UNEM server allowing sensitive data to be read or modified or could cause other unintended behavior

Weakness

A product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

Name Vendor Start Version End Version
Foxman-un Hitachienergy r15a (including) r15a (including)
Foxman-un Hitachienergy r15b-pc4 (including) r15b-pc4 (including)
Foxman-un Hitachienergy r16a (including) r16a (including)
Foxman-un Hitachienergy r16b-pc2 (including) r16b-pc2 (including)
Unem Hitachienergy r15a (including) r15a (including)
Unem Hitachienergy r15b-pc4 (including) r15b-pc4 (including)
Unem Hitachienergy r15b-pc5 (including) r15b-pc5 (including)
Unem Hitachienergy r16a (including) r16a (including)
Unem Hitachienergy r16b-pc2 (including) r16b-pc2 (including)

Potential Mitigations

References