Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xg5w-j24m-8379

Опубликовано: 06 янв. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

DES cipher, which has inadequate encryption strength, is used Hitachi Energy FOXMAN-UN to encrypt user credentials used to access the Network Elements. Successful exploitation allows sensitive information to be decrypted easily. This issue affects * FOXMAN-UN product: FOXMAN-UN R16A, FOXMAN-UN R15B, FOXMAN-UN R15A, FOXMAN-UN R14B, FOXMAN-UN R14A, FOXMAN-UN R11B, FOXMAN-UN R11A, FOXMAN-UN R10C, FOXMAN-UN R9C; * UNEM product: UNEM R16A, UNEM R15B, UNEM R15A, UNEM R14B, UNEM R14A, UNEM R11B, UNEM R11A, UNEM R10C, UNEM R9C. List of CPEs: * cpe:2.3:a:hitachienergy:foxman-un:R16A:::::::* * cpe:2.3:a:hitachienergy:foxman-un:R15B:::::::* * cpe:2.3:a:hitachienergy:foxman-un:R15A:::::::* * cpe:2.3:a:hitachienergy:foxman-un:R14B:::::::* * cpe:2.3:a:hitachienergy:foxman-un:R14A:::::::* * cpe:2.3:a:hitachienergy:foxman-un:R11B:::::::* * cpe:2.3:a:hitachienergy:foxman-un:R11A:::::::* * cpe:2.3:a:hitachienergy:foxman-un:R10C:::::::* * cpe:2.3:a:hitac...

DES cipher, which has inadequate encryption strength, is used Hitachi Energy FOXMAN-UN to encrypt user credentials used to access the Network Elements. Successful exploitation allows sensitive information to be decrypted easily. This issue affects * FOXMAN-UN product: FOXMAN-UN R16A, FOXMAN-UN R15B, FOXMAN-UN R15A, FOXMAN-UN R14B, FOXMAN-UN R14A, FOXMAN-UN R11B, FOXMAN-UN R11A, FOXMAN-UN R10C, FOXMAN-UN R9C; * UNEM product: UNEM R16A, UNEM R15B, UNEM R15A, UNEM R14B, UNEM R14A, UNEM R11B, UNEM R11A, UNEM R10C, UNEM R9C. List of CPEs: * cpe:2.3:a:hitachienergy:foxman-un:R16A:::::::* * cpe:2.3:a:hitachienergy:foxman-un:R15B:::::::* * cpe:2.3:a:hitachienergy:foxman-un:R15A:::::::* * cpe:2.3:a:hitachienergy:foxman-un:R14B:::::::* * cpe:2.3:a:hitachienergy:foxman-un:R14A:::::::* * cpe:2.3:a:hitachienergy:foxman-un:R11B:::::::* * cpe:2.3:a:hitachienergy:foxman-un:R11A:::::::* * cpe:2.3:a:hitachienergy:foxman-un:R10C:::::::* * cpe:2.3:a:hitachienergy:foxman-un:R9C:::::::* * cpe:2.3:a:hitachienergy:unem:R16A:::::::* * cpe:2.3:a:hitachienergy:unem:R15B:::::::* * cpe:2.3:a:hitachienergy:unem:R15A:::::::* * cpe:2.3:a:hitachienergy:unem:R14B:::::::* * cpe:2.3:a:hitachienergy:unem:R14A:::::::* * cpe:2.3:a:hitachienergy:unem:R11B:::::::* * cpe:2.3:a:hitachienergy:unem:R11A:::::::* * cpe:2.3:a:hitachienergy:unem:R10C:::::::* * cpe:2.3:a:hitachienergy:unem:R9C:::::::*

EPSS

Процентиль: 9%
0.00032
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-326

Связанные уязвимости

CVSS3: 7.1
nvd
около 3 лет назад

DES cipher, which has inadequate encryption strength, is used Hitachi Energy FOXMAN-UN to encrypt user credentials used to access the Network Elements. Successful exploitation allows sensitive information to be decrypted easily. This issue affects  * FOXMAN-UN product: FOXMAN-UN R16A, FOXMAN-UN R15B, FOXMAN-UN R15A, FOXMAN-UN R14B, FOXMAN-UN R14A, FOXMAN-UN R11B, FOXMAN-UN R11A, FOXMAN-UN R10C, FOXMAN-UN R9C;  * UNEM product: UNEM R16A, UNEM R15B, UNEM R15A, UNEM R14B, UNEM R14A, UNEM R11B, UNEM R11A, UNEM R10C, UNEM R9C. List of CPEs:  * cpe:2.3:a:hitachienergy:foxman-un:R16A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R15B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R15A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R14B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R14A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R11B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R11A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxma

EPSS

Процентиль: 9%
0.00032
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-326