VYPR

Vendor CVEs

Hitachienergy

All CVEs

108 total · sorted by risk
  • CVE-2024-7941MedAug 27, 2024
    risk 0.28cvss 4.3epss 0.00

    An HTTP parameter may contain a URL value and could cause the web application to redirect the request to the specified URL. By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials.

  • CVE-2019-19091MedApr 2, 2020
    risk 0.28cvss 4.3epss 0.01

    For ABB eSOMS versions 4.0 to 6.0.3, HTTPS responses contain comments with sensitive information about the application. An attacker might use this detail information to specifically craft the attack.

  • CVE-2024-28024MedJun 11, 2024
    risk 0.27cvss 4.1epss 0.00

    A vulnerability exists in the FOXMAN-UN/UNEM in which sensitive information is stored in cleartext within a resource that might be accessible to another control sphere.

  • CVE-2023-1711MedMay 30, 2023
    risk 0.26cvss 4.0epss 0.00

    A vulnerability exists in a FOXMAN-UN and UNEM logging component, it only affects systems that use remote authentication to the network elements. If exploited an attacker could obtain confidential information. List of CPEs: * cpe:2.3:a:hitachienergy:foxman_un:R9C:*:*:*:*:*…

  • CVE-2019-19092LowApr 2, 2020
    risk 0.23cvss 3.5epss 0.01

    ABB eSOMS versions 4.0 to 6.0.3 use ASP.NET Viewstate without Message Authentication Code (MAC). Alterations to Viewstate might thus not be noticed.

  • CVE-2019-19090LowApr 2, 2020
    risk 0.23cvss 3.5epss 0.01

    For ABB eSOMS versions 4.0 to 6.0.2, the Secure Flag is not set in the HTTP response header. Unencrypted connections might access the cookie information, thus making it susceptible to eavesdropping.

  • CVE-2024-41156LowOct 29, 2024
    risk 0.18cvss 2.7epss 0.00

    Profile files from TRO600 series radios are extracted in plain-text and encrypted file formats. Profile files provide potential attackers valuable configuration information about the Tropos network. Profiles can only be exported by authenticated users with higher privilege of…

  • CVE-2023-2622LowNov 1, 2023
    risk 0.18cvss 2.7epss 0.00

    Authenticated clients can read arbitrary files on the MAIN Computer system using the remote procedure call (RPC) of the InspectSetup service endpoint. The low privilege client is then allowed to read arbitrary files that they do not have authorization to read.

Page 3 of 3