CVE Vulnerabilities

CVE-2024-2013

Authentication Bypass Using an Alternate Path or Channel

Published: Jun 11, 2024 | Modified: Nov 21, 2024
CVSS 3.x
10
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An authentication bypass vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway component that if exploited allows attackers without any access to interact with the services and the post-authentication attack surface.

Weakness

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

Name Vendor Start Version End Version
Foxman-un Hitachienergy r15a (including) r15a (including)
Foxman-un Hitachienergy r15b-pc4 (including) r15b-pc4 (including)
Foxman-un Hitachienergy r16a (including) r16a (including)
Foxman-un Hitachienergy r16b-pc2 (including) r16b-pc2 (including)
Unem Hitachienergy r15a (including) r15a (including)
Unem Hitachienergy r15b-pc4 (including) r15b-pc4 (including)
Unem Hitachienergy r15b-pc5 (including) r15b-pc5 (including)
Unem Hitachienergy r16b (including) r16b (including)
Unem Hitachienergy r16b-pc2 (including) r16b-pc2 (including)

Potential Mitigations

References