Vulnerabilites related to Hitachi Energy - XMC20
CVE-2024-2462 (GCVE-0-2024-2462)
Vulnerability from cvelistv5
Published
2024-06-11 12:48
Modified
2024-08-01 19:11
CWE
  • CWE-297 - Improper Validation of Certificate with Host Mismatch
Summary
Allow attackers to intercept or falsify data exchanges between the client and the server
Impacted products
Vendor Product Version
Hitachi Energy FOXMAN-UN Version: 0   <
Patch: FOXMAN-UN R16B PC3
Version: 0   <
Patch: FOXMAN-UN R15B PC5
Version: FOXMAN-UN R16A   <
Version: FOXMAN-UN R15A   <
Create a notification for this product.
   Hitachi Energy FOX61x Version: 0   < FOX61x R16B
Patch: FOX61x R16B
Create a notification for this product.
   Hitachi Energy FOXCST Version: 0   < FOXCST_16.2.1
Patch: FOXCST_16.2.1
Create a notification for this product.
   Hitachi Energy UNEM Version: 0   <
Patch: UNEM R16B PC3
Version: 0   <
Patch: UNEM R15B PC5
Version: UNEM R16A   <
Version: UNEM R15A   <
Create a notification for this product.
   Hitachi Energy XMC20 Version: R16B   <
Create a notification for this product.
   Hitachi Energy ECST Version: ECST_16.2.1   <
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "affected": [
          {
            "cpes": [
              "cpe:2.3:a:hitachi_energy:foxman-un:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unaffected",
            "product": "foxman-un",
            "vendor": "hitachi_energy",
            "versions": [
              {
                "lessThanOrEqual": "FOXMAN-UN R16B PC2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "status": "unaffected",
                "version": "FOXMAN-UN R16B PC3"
              },
              {
                "lessThanOrEqual": "FOXMAN-UN R15B PC4",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "status": "unaffected",
                "version": "FOXMAN-UN R15B PC5"
              },
              {
                "status": "affected",
                "version": "FOXMAN-UN R16A"
              },
              {
                "status": "affected",
                "version": "FOXMAN-UN R15A"
              }
            ]
          },
          {
            "cpes": [
              "cpe:2.3:a:hitachi_energy:fox61x:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unaffected",
            "product": "fox61x",
            "vendor": "hitachi_energy",
            "versions": [
              {
                "lessThan": "FOX61x R16B",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "status": "unaffected",
                "version": "FOX61x R16B"
              }
            ]
          },
          {
            "cpes": [
              "cpe:2.3:a:hitachi_energy:foxcst:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unaffected",
            "product": "foxcst",
            "vendor": "hitachi_energy",
            "versions": [
              {
                "lessThan": "FOXCST_16.2.1",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "status": "unaffected",
                "version": "FOXCST_16.2.1"
              }
            ]
          },
          {
            "cpes": [
              "cpe:2.3:a:hitachi_energy:unem:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unaffected",
            "product": "unem",
            "vendor": "hitachi_energy",
            "versions": [
              {
                "lessThanOrEqual": "UNEM R16B PC2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "status": "unaffected",
                "version": "UNEM R16B PC3"
              },
              {
                "lessThanOrEqual": "UNEM R15B PC4",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "status": "unaffected",
                "version": "UNEM R15B PC5"
              },
              {
                "status": "affected",
                "version": "UNEM R16A"
              },
              {
                "status": "affected",
                "version": "UNEM R15A"
              }
            ]
          },
          {
            "cpes": [
              "cpe:2.3:a:hitachi_energy:xmc20:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unaffected",
            "product": "xmc20",
            "vendor": "hitachi_energy",
            "versions": [
              {
                "status": "affected",
                "version": "R16B"
              }
            ]
          },
          {
            "cpes": [
              "cpe:2.3:a:hitachi_energy:ecst:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unaffected",
            "product": "ecst",
            "vendor": "hitachi_energy",
            "versions": [
              {
                "status": "affected",
                "version": "ECST_16.2.1"
              }
            ]
          }
        ],
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-2462",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-06-12T18:31:01.584910Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-06-12T19:06:16.825Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      },
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-01T19:11:53.576Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://publisher.hitachienergy.com/preview?DocumentId=8DBD000198\u0026languageCode=en\u0026Preview=true"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "FOXMAN-UN",
          "vendor": "Hitachi Energy",
          "versions": [
            {
              "lessThanOrEqual": "FOXMAN-UN R16B PC2",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "FOXMAN-UN R16B PC3",
              "versionType": "custom"
            },
            {
              "lessThanOrEqual": "FOXMAN-UN R15B PC4",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "FOXMAN-UN R15B PC5",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "FOXMAN-UN R16A",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "FOXMAN-UN R15A",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "FOX61x",
          "vendor": "Hitachi Energy",
          "versions": [
            {
              "lessThan": "FOX61x R16B",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "FOX61x R16B",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "FOXCST",
          "vendor": "Hitachi Energy",
          "versions": [
            {
              "lessThan": "FOXCST_16.2.1",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "FOXCST_16.2.1",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "UNEM",
          "vendor": "Hitachi Energy",
          "versions": [
            {
              "lessThanOrEqual": "UNEM R16B PC2",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "UNEM R16B PC3",
              "versionType": "custom"
            },
            {
              "lessThanOrEqual": "UNEM R15B PC4",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "UNEM R15B PC5",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "UNEM R16A",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "UNEM R15A",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "XMC20",
          "vendor": "Hitachi Energy",
          "versions": [
            {
              "status": "affected",
              "version": "R16B",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "ECST",
          "vendor": "Hitachi Energy",
          "versions": [
            {
              "status": "affected",
              "version": "ECST_16.2.1",
              "versionType": "custom"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "Allow attackers to intercept or falsify data exchanges between the client \nand the server\n\n"
            }
          ],
          "value": "Allow attackers to intercept or falsify data exchanges between the client \nand the server"
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "PHYSICAL",
            "baseScore": 6.8,
            "baseSeverity": "MEDIUM",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "HIGH",
            "subConfidentialityImpact": "LOW",
            "subIntegrityImpact": "NONE",
            "userInteraction": "ACTIVE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:L/SI:N/SA:H",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-297",
              "description": "CWE-297 Improper Validation of Certificate with Host Mismatch",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2024-06-11T12:48:57.963Z",
        "orgId": "e383dce4-0c27-4495-91c4-0db157728d17",
        "shortName": "Hitachi Energy"
      },
      "references": [
        {
          "url": "https://publisher.hitachienergy.com/preview?DocumentId=8DBD000198\u0026languageCode=en\u0026Preview=true"
        }
      ],
      "source": {
        "discovery": "UNKNOWN"
      },
      "x_generator": {
        "engine": "Vulnogram 0.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "e383dce4-0c27-4495-91c4-0db157728d17",
    "assignerShortName": "Hitachi Energy",
    "cveId": "CVE-2024-2462",
    "datePublished": "2024-06-11T12:48:57.963Z",
    "dateReserved": "2024-03-14T17:09:59.755Z",
    "dateUpdated": "2024-08-01T19:11:53.576Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

CVE-2024-2461 (GCVE-0-2024-2461)
Vulnerability from cvelistv5
Published
2024-06-11 12:57
Modified
2024-08-01 19:11
CWE
  • CWE-23 - Relative Path Traversal
Summary
If exploited an attacker could traverse the file system to access files or directories that would otherwise be inaccessible
Impacted products
Vendor Product Version
Hitachi Energy FOX61x Version: 0   <
Patch: FOX61x R16B Revision G, version (cesm3_r16b04_07, cesne_r16b04_07, f10ne_r16b04_07)
Version: FOX61x R15B   <
Version: FOX61x R16A
Version: FOX61x R15A
Create a notification for this product.
   Hitachi Energy XMC20 Version: 0   <
Patch: XMC20 R16B Revision D, version (cent2_r16b04_07, co5ne_r16b04_07)
Version: XMC20 R15B   <
Patch: XMC20 R16B Revision D, version (cent2_r16b04_07, co5ne_r16b04_07)
Version: XMC20 R16A   <
Version: XMC20 R15A   <
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-2461",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-06-11T13:58:39.472974Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-06-11T13:58:58.084Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      },
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-01T19:11:53.616Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://publisher.hitachienergy.com/preview?DocumentId=8DBD000202\u0026languageCode=en\u0026Preview=true"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "FOX61x",
          "vendor": "Hitachi Energy",
          "versions": [
            {
              "lessThanOrEqual": "FOX61x R16B Revision E (cesm3_r16b04_02,  cesne_r16b04_02 and  f10ne_r16b04_02)",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "FOX61x R16B Revision G, version (cesm3_r16b04_07,  cesne_r16b04_07, f10ne_r16b04_07)",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "FOX61x R15B",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "FOX61X R16B Revision G,  (cesm3_r16b04_07, cesne_r16b04_07, f10ne_r16b04_07)"
            },
            {
              "status": "affected",
              "version": "FOX61x R16A"
            },
            {
              "status": "affected",
              "version": "FOX61x R15A"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "XMC20",
          "vendor": "Hitachi Energy",
          "versions": [
            {
              "lessThanOrEqual": "XMC20 R16B Revision C (cent2_r16b04_02,  co5ne_r16b04_02)",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "XMC20 R16B Revision D, version  (cent2_r16b04_07, co5ne_r16b04_07)",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "XMC20 R15B",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "XMC20 R16B Revision D, version (cent2_r16b04_07, co5ne_r16b04_07)",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "XMC20 R16A",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "XMC20 R15A",
              "versionType": "custom"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\n\nIf exploited an attacker could traverse the file system to access \nfiles or directories that would otherwise be inaccessible\n\n"
            }
          ],
          "value": "If exploited an attacker could traverse the file system to access \nfiles or directories that would otherwise be inaccessible"
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 6.9,
            "baseSeverity": "MEDIUM",
            "privilegesRequired": "HIGH",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "HIGH",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-23",
              "description": "CWE-23 Relative Path Traversal",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2024-06-11T12:57:04.498Z",
        "orgId": "e383dce4-0c27-4495-91c4-0db157728d17",
        "shortName": "Hitachi Energy"
      },
      "references": [
        {
          "url": "https://publisher.hitachienergy.com/preview?DocumentId=8DBD000202\u0026languageCode=en\u0026Preview=true"
        }
      ],
      "source": {
        "discovery": "UNKNOWN"
      },
      "x_generator": {
        "engine": "Vulnogram 0.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "e383dce4-0c27-4495-91c4-0db157728d17",
    "assignerShortName": "Hitachi Energy",
    "cveId": "CVE-2024-2461",
    "datePublished": "2024-06-11T12:57:04.498Z",
    "dateReserved": "2024-03-14T17:09:59.168Z",
    "dateUpdated": "2024-08-01T19:11:53.616Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}