VYPR
Medium severity6.5NVD Advisory· Published Jun 11, 2024· Updated Jun 17, 2026

CVE-2024-28022

CVE-2024-28022

Description

A vulnerability exists in the UNEM server / APIGateway that if exploited allows a malicious user to perform an arbitrary number of authentication attempts using different passwords, and eventually gain access to other components in the same security realm using the targeted account.

Affected products

11
  • Hitachienergy/unemllm-fuzzy5 versions
    (expand)+ 4 more
    • (no CPE)
    • cpe:2.3:a:hitachienergy:unem:r15a:*:*:*:*:*:*:*
    • cpe:2.3:a:hitachienergy:unem:r15b:*:*:*:*:*:*:*
    • cpe:2.3:a:hitachienergy:unem:r16a:*:*:*:*:*:*:*
    • cpe:2.3:a:hitachienergy:unem:r16b:*:*:*:*:*:*:*
  • Hitachi/UNEMcpe-rescue
    Range: UNEM R16B
  • Hitachi Energy/FOXMAN-UNv5
    Range: FOXMAN-UN R16B
  • cpe:2.3:a:hitachienergy:foxman-un:r15b:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:hitachienergy:foxman-un:r15b:*:*:*:*:*:*:*
    • cpe:2.3:a:hitachienergy:foxman-un:r16a:*:*:*:*:*:*:*
    • cpe:2.3:a:hitachienergy:foxman-un:r16b:*:*:*:*:*:*:*
    • cpe:2.3:a:hitachienergy:foxman-un:r15a:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.