Vulnerabilities > Hitachienergy > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-11-01 CVE-2023-5515 Unspecified vulnerability in Hitachienergy Esoms
The responses for web queries with certain parameters disclose internal path of resources.
network
low complexity
hitachienergy
5.3
2023-11-01 CVE-2023-5516 Unspecified vulnerability in Hitachienergy Esoms
Poorly constructed webap requests and URI components with special characters trigger unhandled errors and exceptions, disclosing information about the underlying technology and other sensitive information details.
network
low complexity
hitachienergy
5.3
2023-05-30 CVE-2023-1711 Improper Encoding or Escaping of Output vulnerability in Hitachienergy Foxman-Un and Unem
A vulnerability exists in a FOXMAN-UN and UNEM logging component, it only affects systems that use remote authentication to the network elements.
local
low complexity
hitachienergy CWE-116
4.4
2023-01-05 CVE-2021-40341 Inadequate Encryption Strength vulnerability in Hitachienergy Foxman-Un and Unem
DES cipher, which has inadequate encryption strength, is used Hitachi Energy FOXMAN-UN to encrypt user credentials used to access the Network Elements.
local
low complexity
hitachienergy CWE-326
5.5
2023-01-05 CVE-2022-3928 Use of Hard-coded Credentials vulnerability in Hitachienergy Foxman-Un and Unem
Hardcoded credential is found in affected products' message queue.
local
low complexity
hitachienergy CWE-798
5.5
2022-11-22 CVE-2022-2513 Cleartext Storage of Sensitive Information vulnerability in Hitachienergy products
A vulnerability exists in the Intelligent Electronic Device (IED) Connectivity Package (ConnPack) credential storage function in Hitachi Energy’s PCM600 product included in the versions listed below, where IEDs credentials are stored in a cleartext format in the PCM600 database and logs files.
local
low complexity
hitachienergy CWE-312
5.5
2022-09-14 CVE-2022-1778 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Hitachienergy Microscada X Sys600
Improper Input Validation vulnerability in Hitachi Energy MicroSCADA X SYS600 while reading a specific configuration file causes a buffer-overflow that causes a failure to start the SYS600.
local
low complexity
hitachienergy CWE-119
4.4
2022-06-07 CVE-2021-35530 Unspecified vulnerability in Hitachienergy Txpert HUB Coretec 4 Firmware
A vulnerability in the application authentication and authorization mechanism in Hitachi Energy's TXpert Hub CoreTec 4, that depends on a token validation of the session identifier, allows an unauthorized modified message to be executed in the server enabling an unauthorized actor to change an existing user password, and further gain authorized access into the system via login mechanism.
local
low complexity
hitachienergy
6.7
2022-06-07 CVE-2021-35531 OS Command Injection vulnerability in Hitachienergy Txpert HUB Coretec 4 Firmware
Improper Input Validation vulnerability in a particular configuration setting field of Hitachi Energy TXpert Hub CoreTec 4 product, allows an attacker with access to an authorized user with ADMIN or ENGINEER role rights to inject an OS command that is executed by the system.
local
low complexity
hitachienergy CWE-78
6.7
2022-03-11 CVE-2021-27414 Improper Restriction of Rendered UI Layers or Frames vulnerability in Hitachienergy Ellipse Enterprise Asset Management
An attacker could trick a user of Hitachi ABB Power Grids Ellipse Enterprise Asset Management (EAM) versions prior to and including 9.0.25 into visiting a malicious website posing as a login page for the Ellipse application and gather authentication credentials.
network
low complexity
hitachienergy CWE-1021
6.1