CVE-2024-28022: Hitachienergy Foxman-Un
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
A vulnerability exists in the UNEM server / APIGateway that if exploited allows a malicious user to perform an arbitrary number of authentication attempts using different passwords, and eventually gain access to other components in the same security realm using the targeted account.
Affected products
- Hitachienergy Foxman-Un: version r15a only; version r15b only; version r16a only; version r16b only
- Hitachienergy Unem: version r15a only; version r15b only; version r16a only; version r16b only
Published 2024-06-11. Last modified 2026-06-17.