Where
AND
-Infinity
0
Severity
6.5
AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L

A vulnerability exists in the UNEM server / APIGateway that if exploited allows a malicious user to perform an arbitrary number of authentication attempts using different passwords, and eventually gain access to other components in the same security realm using the targeted account.

First published (updated )
Severity
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the DES implementation, the affected product versions use a default key for encryption. Successful exploitation allows an attacker to obtain sensitive information and gain access to the network elements that are managed by the affected products versions.

This issue affects

FOXMAN-UN product: FOXMAN-UN R16A, FOXMAN-UN R15B, FOXMAN-UN R15A, FOXMAN-UN R14B, FOXMAN-UN R14A, FOXMAN-UN R11B, FOXMAN-UN R11A, FOXMAN-UN R10C, FOXMAN-UN R9C; UNEM product: UNEM R16A, UNEM R15B, UNEM R15A, UNEM R14B, UNEM R14A, UNEM R11B, UNEM R11A, UNEM R10C, UNEM R9C.

List of CPEs: cpe:2.3:a:hitachienergy:foxman-un:R16A::::::: cpe:2.3:a:hitachienergy:foxman-un:R15B::::::: cpe:2.3:a:hitachienergy:foxman-un:R15A::::::: cpe:2.3:a:hitachienergy:foxman-un:R14B::::::: cpe:2.3:a:hitachienergy:foxman-un:R14A::::::: cpe:2.3:a:hitachienergy:foxman-un:R11B::::::: cpe:2.3:a:hitachienergy:foxman-un:R11A::::::: cpe:2.3:a:hitachienergy:foxman-un:R10C::::::: cpe:2.3:a:hitachienergy:foxman-un:R9C::::::: cpe:2.3:a:hitachienergy:unem:R16A::::::: cpe:2.3:a:hitachienergy:unem:R15B::::::: cpe:2.3:a:hitachienergy:unem:R15A::::::: cpe:2.3:a:hitachienergy:unem:R14B::::::: cpe:2.3:a:hitachienergy:unem:R14A::::::: cpe:2.3:a:hitachienergy:unem:R11B::::::: cpe:2.3:a:hitachienergy:unem:R11A::::::: cpe:2.3:a:hitachienergy:unem:R10C::::::: cpe:2.3:a:hitachienergy:unem:R9C:::::::

1 / 2
Source: MITRE
First published (updated )
Severity
7.1
Weak Encryption
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

DES cipher, which has inadequate encryption strength, is used Hitachi Energy FOXMAN-UN to encrypt user credentials used to access the Network Elements. Successful exploitation allows sensitive information to be decrypted easily. This issue affects

FOXMAN-UN product: FOXMAN-UN R16A, FOXMAN-UN R15B, FOXMAN-UN R15A, FOXMAN-UN R14B, FOXMAN-UN R14A, FOXMAN-UN R11B, FOXMAN-UN R11A, FOXMAN-UN R10C, FOXMAN-UN R9C;  UNEM product: UNEM R16A, UNEM R15B, UNEM R15A, UNEM R14B, UNEM R14A, UNEM R11B, UNEM R11A, UNEM R10C, UNEM R9C.

List of CPEs:  cpe:2.3:a:hitachienergy:foxman-un:R16A::::::: cpe:2.3:a:hitachienergy:foxman-un:R15B::::::: cpe:2.3:a:hitachienergy:foxman-un:R15A::::::: cpe:2.3:a:hitachienergy:foxman-un:R14B::::::: cpe:2.3:a:hitachienergy:foxman-un:R14A::::::: cpe:2.3:a:hitachienergy:foxman-un:R11B::::::: cpe:2.3:a:hitachienergy:foxman-un:R11A::::::: cpe:2.3:a:hitachienergy:foxman-un:R10C::::::: cpe:2.3:a:hitachienergy:foxman-un:R9C::::::: cpe:2.3:a:hitachienergy:unem:R16A::::::: cpe:2.3:a:hitachienergy:unem:R15B::::::: cpe:2.3:a:hitachienergy:unem:R15A::::::: cpe:2.3:a:hitachienergy:unem:R14B::::::: cpe:2.3:a:hitachienergy:unem:R14A::::::: cpe:2.3:a:hitachienergy:unem:R11B::::::: cpe:2.3:a:hitachienergy:unem:R11A::::::: cpe:2.3:a:hitachienergy:unem:R10C::::::: cpe:2.3:a:hitachienergy:unem:R9C:::::::

1 / 2
Source: MITRE
First published (updated )
Severity
4.4
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

A vulnerability exists in a FOXMAN-UN and UNEM logging component, it only affects systems that use remote authentication to the network elements. If exploited an attacker could obtain confidential information.

List of CPEs: cpe:2.3:a:hitachienergy:foxmanun:R9C::::::: cpe:2.3:a:hitachienergy:foxmanun:R10C:::::::

cpe:2.3:a:hitachienergy:foxmanun:R11A:::::::

cpe:2.3:a:hitachienergy:foxmanun:R11B:::::::

cpe:2.3:a:hitachienergy:foxmanun:R14A:::::::

cpe:2.3:a:hitachienergy:foxmanun:R14B:::::::

cpe:2.3:a:hitachienergy:foxmanun:R15A:::::::

cpe:2.3:a:hitachienergy:foxmanun:R15B:::::::

cpe:2.3:a:hitachienergy:foxmanun:R16A:::::::

cpe:2.3:a:hitachienergy:unem:R9C::::::: cpe:2.3:a:hitachienergy: unem :R10C:::::::

cpe:2.3:a:hitachienergy: unem :R11A:::::::

cpe:2.3:a:hitachienergy: unem :R11B:::::::

cpe:2.3:a:hitachienergy: unem :R14A:::::::

cpe:2.3:a:hitachienergy: unem :R14B:::::::

cpe:2.3:a:hitachienergy: unem :R15A:::::::

cpe:2.3:a:hitachienergy: unem :R15B:::::::

cpe:2.3:a:hitachienergy: unem :R16A:::::::

Remedy

The vulnerability is remediated in FOXMAN-UN/UNEM R16B. Please upgrade to R16B when released or apply general mitigation factors.
First published (updated )
Severity
9.9
AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

A user/password reuse vulnerability exists in the FOXMAN-UN/UNEM application and server management. If exploited a malicious high-privileged user could use the passwords and login information through complex routines to extend access on the server and other services.

First published (updated )
Severity
4.1
AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N

A vulnerability exists in the FOXMAN-UN/UNEM in which sensitive information is stored in cleartext within a resource that might be accessible to another control sphere.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203