VYPR
Unrated severityNVD Advisory· Published Jan 5, 2023· Updated Apr 10, 2025

Communication between the client and server partially using CORBA over TCP/IP

CVE-2022-3929

Description

Communication between the client and the server application of the affected products is partially done using CORBA (Common Object Request Broker Architecture) over TCP/IP. This protocol is not encrypted and allows tracing of internal messages.

This issue affects

  • FOXMAN-UN product: FOXMAN-UN R15B, FOXMAN-UN R15A, FOXMAN-UN R14B, FOXMAN-UN R14A, FOXMAN-UN R11B, FOXMAN-UN R11A, FOXMAN-UN R10C, FOXMAN-UN R9C;
  • UNEM product: UNEM R15B, UNEM R15A, UNEM R14B, UNEM R14A, UNEM R11B, UNEM R11A, UNEM R10C, UNEM R9C.

List of CPEs: * cpe:2.3:a:hitachienergy:foxman-un:R15B:*:*:*:*:*:*:*

  • cpe:2.3:a:hitachienergy:foxman-un:R15A:*:*:*:*:*:*:*
  • cpe:2.3:a:hitachienergy:foxman-un:R14B:*:*:*:*:*:*:*
  • cpe:2.3:a:hitachienergy:foxman-un:R14A:*:*:*:*:*:*:*
  • cpe:2.3:a:hitachienergy:foxman-un:R11B:*:*:*:*:*:*:*
  • cpe:2.3:a:hitachienergy:foxman-un:R11A:*:*:*:*:*:*:*
  • cpe:2.3:a:hitachienergy:foxman-un:R10C:*:*:*:*:*:*:*
  • cpe:2.3:a:hitachienergy:foxman-un:R9C:*:*:*:*:*:*:*
  • cpe:2.3:a:hitachienergy:unem:R15B:*:*:*:*:*:*:*
  • cpe:2.3:a:hitachienergy:unem:R15A:*:*:*:*:*:*:*
  • cpe:2.3:a:hitachienergy:unem:R14B:*:*:*:*:*:*:*
  • cpe:2.3:a:hitachienergy:unem:R14A:*:*:*:*:*:*:*
  • cpe:2.3:a:hitachienergy:unem:R11B:*:*:*:*:*:*:*
  • cpe:2.3:a:hitachienergy:unem:R11A:*:*:*:*:*:*:*
  • cpe:2.3:a:hitachienergy:unem:R10C:*:*:*:*:*:*:*
  • cpe:2.3:a:hitachienergy:unem:R9C:*:*:*:*:*:*:*

Affected products

2
  • Hitachi Energy/FOXMAN-UNv5
    Range: FOXMAN-UN R15B
  • Hitachi/UNEMcpe-rescue
    Range: UNEM R15B

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.