Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f6c3-2788-h964

Опубликовано: 06 янв. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Communication between the client and the server application of the affected products is partially done using CORBA (Common Object Request Broker Architecture) over TCP/IP. This protocol is not encrypted and allows tracing of internal messages. This issue affects * FOXMAN-UN product: FOXMAN-UN R15B, FOXMAN-UN R15A, FOXMAN-UN R14B, FOXMAN-UN R14A, FOXMAN-UN R11B, FOXMAN-UN R11A, FOXMAN-UN R10C, FOXMAN-UN R9C; * UNEM product: UNEM R15B, UNEM R15A, UNEM R14B, UNEM R14A, UNEM R11B, UNEM R11A, UNEM R10C, UNEM R9C. List of CPEs: * cpe:2.3:a:hitachienergy:foxman-un:R15B:::::::* * cpe:2.3:a:hitachienergy:foxman-un:R15A:::::::* * cpe:2.3:a:hitachienergy:foxman-un:R14B:::::::* * cpe:2.3:a:hitachienergy:foxman-un:R14A:::::::* * cpe:2.3:a:hitachienergy:foxman-un:R11B:::::::* * cpe:2.3:a:hitachienergy:foxman-un:R11A:::::::* * cpe:2.3:a:hitachienergy:foxman-un:R10C:::::::* * cpe:2.3:a:hitachienergy:foxman-un:R9C:::::::* * cpe:2.3:a:hitachienergy:unem...

Communication between the client and the server application of the affected products is partially done using CORBA (Common Object Request Broker Architecture) over TCP/IP. This protocol is not encrypted and allows tracing of internal messages. This issue affects * FOXMAN-UN product: FOXMAN-UN R15B, FOXMAN-UN R15A, FOXMAN-UN R14B, FOXMAN-UN R14A, FOXMAN-UN R11B, FOXMAN-UN R11A, FOXMAN-UN R10C, FOXMAN-UN R9C; * UNEM product: UNEM R15B, UNEM R15A, UNEM R14B, UNEM R14A, UNEM R11B, UNEM R11A, UNEM R10C, UNEM R9C. List of CPEs: * cpe:2.3:a:hitachienergy:foxman-un:R15B:::::::* * cpe:2.3:a:hitachienergy:foxman-un:R15A:::::::* * cpe:2.3:a:hitachienergy:foxman-un:R14B:::::::* * cpe:2.3:a:hitachienergy:foxman-un:R14A:::::::* * cpe:2.3:a:hitachienergy:foxman-un:R11B:::::::* * cpe:2.3:a:hitachienergy:foxman-un:R11A:::::::* * cpe:2.3:a:hitachienergy:foxman-un:R10C:::::::* * cpe:2.3:a:hitachienergy:foxman-un:R9C:::::::* * cpe:2.3:a:hitachienergy:unem:R15B:::::::* * cpe:2.3:a:hitachienergy:unem:R15A:::::::* * cpe:2.3:a:hitachienergy:unem:R14B:::::::* * cpe:2.3:a:hitachienergy:unem:R14A:::::::* * cpe:2.3:a:hitachienergy:unem:R11B:::::::* * cpe:2.3:a:hitachienergy:unem:R11A:::::::* * cpe:2.3:a:hitachienergy:unem:R10C:::::::* * cpe:2.3:a:hitachienergy:unem:R9C:::::::*

EPSS

Процентиль: 49%
0.00261
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-319

Связанные уязвимости

CVSS3: 8.3
nvd
около 3 лет назад

Communication between the client and the server application of the affected products is partially done using CORBA (Common Object Request Broker Architecture) over TCP/IP. This protocol is not encrypted and allows tracing of internal messages. This issue affects * FOXMAN-UN product: FOXMAN-UN R15B, FOXMAN-UN R15A, FOXMAN-UN R14B, FOXMAN-UN R14A, FOXMAN-UN R11B, FOXMAN-UN R11A, FOXMAN-UN R10C, FOXMAN-UN R9C; * UNEM product: UNEM R15B, UNEM R15A, UNEM R14B, UNEM R14A, UNEM R11B, UNEM R11A, UNEM R10C, UNEM R9C. List of CPEs: * cpe:2.3:a:hitachienergy:foxman-un:R15B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R15A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R14B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R14A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R11B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R11A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R10C:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R9C:*:*

EPSS

Процентиль: 49%
0.00261
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-319