« Volver al listado

CVE-2024-28020

Estado: ModificadaAlta (8)—

A user/password reuse vulnerability exists in the FOXMAN-UN/UNEM application and server management. If exploited a malicious high-privileged user could use the passwords and login information through complex routines to extend access on the server and other services.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-28020",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-28020",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-06-11T20:27:26.873565Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cybersecurity@hitachienergy.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 1.3
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 1.3
      }
    ]
  },
  "affected": [
    {
      "source": "cybersecurity@hitachienergy.com",
      "affectedData": [
        {
          "vendor": "Hitachi Energy",
          "product": "FOXMAN-UN",
          "versions": [
            {
              "status": "affected",
              "version": "FOXMAN-UN R16B"
            },
            {
              "status": "affected",
              "version": "FOXMAN-UN R15B"
            },
            {
              "status": "affected",
              "version": "FOXMAN-UN R16A"
            },
            {
              "status": "affected",
              "version": "FOXMAN-UN R15A"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Hitachi Energy",
          "product": "UNEM",
          "versions": [
            {
              "status": "affected",
              "version": "UNEM R16B"
            },
            {
              "status": "affected",
              "version": "UNEM R15B"
            },
            {
              "status": "affected",
              "version": "UNEM R16A"
            },
            {
              "status": "affected",
              "version": "UNEM R15A"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:hitachienergy:foxman-un:*:*:*:*:*:*:*:*"
          ],
          "vendor": "hitachienergy",
          "product": "foxman-un",
          "versions": [
            {
              "status": "affected",
              "version": "r16b"
            },
            {
              "status": "affected",
              "version": "r15b"
            },
            {
              "status": "affected",
              "version": "r15a"
            },
            {
              "status": "affected",
              "version": "r16a"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:2.3:a:hitachienergy:unem:*:*:*:*:*:*:*:*"
          ],
          "vendor": "hitachienergy",
          "product": "unem",
          "versions": [
            {
              "status": "affected",
              "version": "r15b"
            },
            {
              "status": "affected",
              "version": "r16b"
            },
            {
              "status": "affected",
              "version": "r15a"
            },
            {
              "status": "affected",
              "version": "r16a"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-06-11T19:16:05.787",
  "references": [
    {
      "url": "https://publisher.hitachienergy.com/preview?DocumentId=8DBD000194&languageCode=en&Preview=true",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cybersecurity@hitachienergy.com"
    },
    {
      "url": "https://publisher.hitachienergy.com/preview?DocumentId=8DBD000201&languageCode=en&Preview=true",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cybersecurity@hitachienergy.com"
    },
    {
      "url": "https://publisher.hitachienergy.com/preview?DocumentId=8DBD000194&languageCode=en&Preview=true",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://publisher.hitachienergy.com/preview?DocumentId=8DBD000201&languageCode=en&Preview=true",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cybersecurity@hitachienergy.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-286"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A user/password reuse vulnerability exists in the FOXMAN-UN/UNEM application\nand server management. If exploited a malicious high-privileged\nuser could use the passwords and login information through complex routines to extend access on the server and other services."
    },
    {
      "lang": "es",
      "value": "Existe una vulnerabilidad de reutilización de usuario/contraseña en la administración de aplicaciones y servidores de FOXMAN-UN/UNEM. Si se explota, un usuario malintencionado podría utilizar las contraseñas y la información de inicio de sesión para ampliar el acceso al servidor y a otros servicios."
    }
  ],
  "lastModified": "2026-06-17T07:20:49.330",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:hitachienergy:foxman-un:r15a:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A7593C74-2882-45D3-AB32-3A45E3AECAAE"
            },
            {
              "criteria": "cpe:2.3:a:hitachienergy:foxman-un:r15b:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "47606044-296D-4561-B9DC-82659BC666F2"
            },
            {
              "criteria": "cpe:2.3:a:hitachienergy:foxman-un:r16a:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7EE987B2-0620-44BB-AEA7-4E20CBE44822"
            },
            {
              "criteria": "cpe:2.3:a:hitachienergy:foxman-un:r16b:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AE743C56-A17F-4FA7-9998-0C767E07518A"
            },
            {
              "criteria": "cpe:2.3:a:hitachienergy:unem:r15a:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E78C9E5B-5876-4F15-A98A-359193287446"
            },
            {
              "criteria": "cpe:2.3:a:hitachienergy:unem:r15b:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C3168F38-7B9E-4F4D-B6D0-1BAFB5FE05F5"
            },
            {
              "criteria": "cpe:2.3:a:hitachienergy:unem:r16a:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7ABB4A53-07A0-4F9A-824B-A1AC71CCB44E"
            },
            {
              "criteria": "cpe:2.3:a:hitachienergy:unem:r16b:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ADA6755A-0553-4246-B462-7580B080FDEF"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cybersecurity@hitachienergy.com"
}