CVE-2024-2013: Hitachienergy Foxman-Un

Critical severity, CVSS 10.0. EPSS: 0.7% chance of exploitation in the next 30 days.

An authentication bypass vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway component that if exploited allows attackers without any access to interact with the services and the post-authentication attack surface.

Affected products

  • Hitachienergy Foxman-Un: version r15a only; version r15b only; version r16a only; version r16b only
  • Hitachienergy Unem: version r15a only; version r15b only; version r16b only

Published 2024-06-11. Last modified 2026-06-17.