Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-40341

Опубликовано: 05 янв. 2023
Источник: nvd
CVSS3: 7.1
CVSS3: 5.5
EPSS Низкий

Описание

DES cipher, which has inadequate encryption strength, is used Hitachi Energy FOXMAN-UN to encrypt user credentials used to access the Network Elements. Successful exploitation allows sensitive information to be decrypted easily. This issue affects 

  • FOXMAN-UN product: FOXMAN-UN R16A, FOXMAN-UN R15B, FOXMAN-UN R15A, FOXMAN-UN R14B, FOXMAN-UN R14A, FOXMAN-UN R11B, FOXMAN-UN R11A, FOXMAN-UN R10C, FOXMAN-UN R9C; 
  • UNEM product: UNEM R16A, UNEM R15B, UNEM R15A, UNEM R14B, UNEM R14A, UNEM R11B, UNEM R11A, UNEM R10C, UNEM R9C.

List of CPEs: 

  • cpe:2.3:a:hitachienergy:foxman-un:R16A:::::::*
  • cpe:2.3:a:hitachienergy:foxman-un:R15B:::::::*
  • cpe:2.3:a:hitachienergy:foxman-un:R15A:::::::*
  • cpe:2.3:a:hitachienergy:foxman-un:R14B:::::::*
  • cpe:2.3:a:hitachienergy:foxman-un:R14A:::::::*
  • cpe:2.3:a:hitachienergy:foxman-un:R11B:::::::*
  • cpe:2.3:a:hitachienergy:foxman-un:R11A:::::::*
  • cpe:2.3:a:hitachienergy:foxma

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:hitachienergy:foxman-un:r9c:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:foxman-un:r10c:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:foxman-un:r11a:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:foxman-un:r11b:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:foxman-un:r14a:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:foxman-un:r14b:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:foxman-un:r15a:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:foxman-un:r15b:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:foxman-un:r16a:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:unem:r9c:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:unem:r10c:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:unem:r11a:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:unem:r11b:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:unem:r14a:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:unem:r14b:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:unem:r15a:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:unem:r15b:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:unem:r16a:*:*:*:*:*:*:*

EPSS

Процентиль: 9%
0.00032
Низкий

7.1 High

CVSS3

5.5 Medium

CVSS3

Дефекты

CWE-326
CWE-326

Связанные уязвимости

CVSS3: 5.5
github
около 3 лет назад

DES cipher, which has inadequate encryption strength, is used Hitachi Energy FOXMAN-UN to encrypt user credentials used to access the Network Elements. Successful exploitation allows sensitive information to be decrypted easily. This issue affects * FOXMAN-UN product: FOXMAN-UN R16A, FOXMAN-UN R15B, FOXMAN-UN R15A, FOXMAN-UN R14B, FOXMAN-UN R14A, FOXMAN-UN R11B, FOXMAN-UN R11A, FOXMAN-UN R10C, FOXMAN-UN R9C; * UNEM product: UNEM R16A, UNEM R15B, UNEM R15A, UNEM R14B, UNEM R14A, UNEM R11B, UNEM R11A, UNEM R10C, UNEM R9C. List of CPEs: * cpe:2.3:a:hitachienergy:foxman-un:R16A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R15B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R15A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R14B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R14A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R11B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R11A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R10C:*:*:*:*:*:*:* * cpe:2.3:a:hitac...

EPSS

Процентиль: 9%
0.00032
Низкий

7.1 High

CVSS3

5.5 Medium

CVSS3

Дефекты

CWE-326
CWE-326