Lucene search

K
cve[email protected]CVE-2024-2012
HistoryJun 11, 2024 - 2:15 p.m.

CVE-2024-2012

2024-06-1114:15:11
CWE-288
web.nvd.nist.gov
27
cve-2024-2012
foxman-un/unem
server
api gateway
unauthorized code execution
sensitive data

9.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

9.2 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway that if exploited an attacker could use to allow unintended commands or
code to be executed on the UNEM server allowing sensitive data to
be read or modified or could cause other unintended behavior

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "FOXMAN-UN",
    "vendor": "Hitachi Energy",
    "versions": [
      {
        "status": "affected",
        "version": "FOXMAN-UN R16B PC2",
        "versionType": "custom"
      },
      {
        "lessThanOrEqual": "FOXMAN-UN R16B PC4",
        "status": "unaffected",
        "version": "FOXMAN-UN R16B PC3",
        "versionType": "custom"
      },
      {
        "status": "affected",
        "version": "FOXMAN-UN R15B PC4",
        "versionType": "custom"
      },
      {
        "status": "unaffected",
        "version": "FOXMAN-UN R15B PC5",
        "versionType": "custom"
      },
      {
        "status": "affected",
        "version": "FOXMAN-UN R16A",
        "versionType": "custom"
      },
      {
        "status": "affected",
        "version": "FOXMAN-UN R15A",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "UNEM",
    "vendor": "Hitachi Energy",
    "versions": [
      {
        "status": "affected",
        "version": "UNEM R16B PC2",
        "versionType": "custom"
      },
      {
        "lessThanOrEqual": "UNEM R16B PC4",
        "status": "unaffected",
        "version": "UNEM R16B PC3",
        "versionType": "custom"
      },
      {
        "status": "affected",
        "version": "UNEM R15B PC4",
        "versionType": "custom"
      },
      {
        "status": "affected",
        "version": "UNEM R15B PC5",
        "versionType": "custom"
      },
      {
        "status": "affected",
        "version": "UNEM R15A",
        "versionType": "custom"
      },
      {
        "status": "affected",
        "version": "UNEM R16A",
        "versionType": "custom"
      }
    ]
  }
]

9.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

9.2 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

Related for CVE-2024-2012