CVE Vulnerabilities

CVE-2024-28021

Improper Certificate Validation

Published: Jun 11, 2024 | Modified: Aug 15, 2024
CVSS 3.x
7.4
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability exists in the FOXMAN-UN/UNEM server that affects the message queueing mechanism’s certificate validation. If exploited an attacker could spoof a trusted entity causing a loss of confidentiality and integrity.

Weakness 

The product does not validate, or incorrectly validates, a certificate.

Affected Software 

Name Vendor Start Version End Version
Foxman-un Hitachienergy r15b-pc4 (including) r15b-pc4 (including)
Foxman-un Hitachienergy r16b-pc2 (including) r16b-pc2 (including)
Foxman_un Hitachienergy r15a (including) r15a (including)
Foxman_un Hitachienergy r16a (including) r16a (including)
Unem Hitachienergy r15a (including) r15a (including)
Unem Hitachienergy r15b-pc4 (including) r15b-pc4 (including)
Unem Hitachienergy r16a (including) r16a (including)
Unem Hitachienergy r16b-pc2 (including) r16b-pc2 (including)

Potential Mitigations 

References