Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vgqf-5fqh-5xqq

Опубликовано: 06 янв. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

Hardcoded credential is found in affected products' message queue. An attacker that manages to exploit this vulnerability will be able to access data to the internal message queue. This issue affects * FOXMAN-UN product: FOXMAN-UN R15B, FOXMAN-UN R15A, FOXMAN-UN R14B, FOXMAN-UN R14A, FOXMAN-UN R11B, FOXMAN-UN R11A, FOXMAN-UN R10C, FOXMAN-UN R9C; * UNEM product: UNEM R15B, UNEM R15A, UNEM R14B, UNEM R14A, UNEM R11B, UNEM R11A, UNEM R10C, UNEM R9C. List of CPEs: * cpe:2.3:a:hitachienergy:foxman-un:R15B:::::::* * cpe:2.3:a:hitachienergy:foxman-un:R15A:::::::* * cpe:2.3:a:hitachienergy:foxman-un:R14B:::::::* * cpe:2.3:a:hitachienergy:foxman-un:R14A:::::::* * cpe:2.3:a:hitachienergy:foxman-un:R11B:::::::* * cpe:2.3:a:hitachienergy:foxman-un:R11A:::::::* * cpe:2.3:a:hitachienergy:foxman-un:R10C:::::::* * cpe:2.3:a:hitachienergy:foxman-un:R9C:::::::* * cpe:2.3:a:hitachienergy:unem:R15B:::::::* * cpe:2.3:a:hitachienergy:unem:R15A::::...

Hardcoded credential is found in affected products' message queue. An attacker that manages to exploit this vulnerability will be able to access data to the internal message queue. This issue affects * FOXMAN-UN product: FOXMAN-UN R15B, FOXMAN-UN R15A, FOXMAN-UN R14B, FOXMAN-UN R14A, FOXMAN-UN R11B, FOXMAN-UN R11A, FOXMAN-UN R10C, FOXMAN-UN R9C; * UNEM product: UNEM R15B, UNEM R15A, UNEM R14B, UNEM R14A, UNEM R11B, UNEM R11A, UNEM R10C, UNEM R9C. List of CPEs: * cpe:2.3:a:hitachienergy:foxman-un:R15B:::::::* * cpe:2.3:a:hitachienergy:foxman-un:R15A:::::::* * cpe:2.3:a:hitachienergy:foxman-un:R14B:::::::* * cpe:2.3:a:hitachienergy:foxman-un:R14A:::::::* * cpe:2.3:a:hitachienergy:foxman-un:R11B:::::::* * cpe:2.3:a:hitachienergy:foxman-un:R11A:::::::* * cpe:2.3:a:hitachienergy:foxman-un:R10C:::::::* * cpe:2.3:a:hitachienergy:foxman-un:R9C:::::::* * cpe:2.3:a:hitachienergy:unem:R15B:::::::* * cpe:2.3:a:hitachienergy:unem:R15A:::::::* * cpe:2.3:a:hitachienergy:unem:R14B:::::::* * cpe:2.3:a:hitachienergy:unem:R14A:::::::* * cpe:2.3:a:hitachienergy:unem:R11B:::::::* * cpe:2.3:a:hitachienergy:unem:R11A:::::::* * cpe:2.3:a:hitachienergy:unem:R10C:::::::* * cpe:2.3:a:hitachienergy:unem:R9C:::::::*

EPSS

Процентиль: 13%
0.00043
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 7.1
nvd
около 3 лет назад

Hardcoded credential is found in affected products' message queue. An attacker that manages to exploit this vulnerability will be able to access data to the internal message queue. This issue affects * FOXMAN-UN product: FOXMAN-UN R15B, FOXMAN-UN R15A, FOXMAN-UN R14B, FOXMAN-UN R14A, FOXMAN-UN R11B, FOXMAN-UN R11A, FOXMAN-UN R10C, FOXMAN-UN R9C; * UNEM product: UNEM R15B, UNEM R15A, UNEM R14B, UNEM R14A, UNEM R11B, UNEM R11A, UNEM R10C, UNEM R9C. List of CPEs: * cpe:2.3:a:hitachienergy:foxman-un:R15B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R15A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R14B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R14A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R11B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R11A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R10C:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R9C:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:unem:R15B:*:*:*:*:*:*:

EPSS

Процентиль: 13%
0.00043
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-798