Vulnerabilities > Hitachienergy > Foxman UN

DATE CVE VULNERABILITY TITLE RISK
2023-01-05 CVE-2022-3927 Use of Hard-coded Credentials vulnerability in Hitachienergy Foxman-Un and Unem
The affected products store both public and private key that are used to sign and protect Custom Parameter Set (CPS) file from modification.
network
low complexity
hitachienergy CWE-798
critical
9.8
2023-01-05 CVE-2022-3928 Use of Hard-coded Credentials vulnerability in Hitachienergy Foxman-Un and Unem
Hardcoded credential is found in affected products' message queue.
local
low complexity
hitachienergy CWE-798
5.5
2023-01-05 CVE-2022-3929 Cleartext Transmission of Sensitive Information vulnerability in Hitachienergy Foxman-Un and Unem
Communication between the client and the server application of the affected products is partially done using CORBA (Common Object Request Broker Architecture) over TCP/IP.
network
low complexity
hitachienergy CWE-319
critical
9.8