An authentication bypass vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway component that if exploited allows attackers without any access to interact with the services and the post-authentication attack surface.
A product requires authentication, but the product has an alternate path or channel that does not require authentication.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Foxman-un | Hitachienergy | r15a (including) | r15a (including) |
Foxman-un | Hitachienergy | r15b-pc4 (including) | r15b-pc4 (including) |
Foxman-un | Hitachienergy | r16a (including) | r16a (including) |
Foxman-un | Hitachienergy | r16b-pc2 (including) | r16b-pc2 (including) |
Unem | Hitachienergy | r15a (including) | r15a (including) |
Unem | Hitachienergy | r15b-pc4 (including) | r15b-pc4 (including) |
Unem | Hitachienergy | r15b-pc5 (including) | r15b-pc5 (including) |
Unem | Hitachienergy | r16b (including) | r16b (including) |
Unem | Hitachienergy | r16b-pc2 (including) | r16b-pc2 (including) |