ZeroHour

CVE-2024-28022

CVSS 3.1
6.5 medium
EPSS
<1%p29
Published
()
Modified
Description

A vulnerability exists in the UNEM server / APIGateway that if exploited allows a malicious user to perform an arbitrary number of authentication attempts using different passwords, and eventually gain access to other components in the same security realm using the targeted account.

Vendors
hitachienergy
Products
foxman-un, unem
Weakness
CWE-307
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.