← Back to browse · API

CVE-2024-2013

Severity
CRITICAL
CVSS
10.0
EPSS
0.0068
Risk score
40.24
CISA KEV
No
PoC
No
Published
2024-06-11
Modified
2024-08-01
First seen
2026-08-08
Aliases
EUVD-2024-26983, GHSA-FC83-86WW-F7QW
Products
Hitachi Energy:FOXMAN-UN FOXMAN-UN R15A, Hitachi Energy:FOXMAN-UN FOXMAN-UN R15B PC4, Hitachi Energy:FOXMAN-UN FOXMAN-UN R16A, Hitachi Energy:FOXMAN-UN FOXMAN-UN R16B PC2, Hitachi Energy:UNEM UNEM R15A, Hitachi Energy:UNEM UNEM R15B PC4, Hitachi Energy:UNEM UNEM R15B PC5, Hitachi Energy:UNEM UNEM R16B, Hitachi Energy:UNEM UNEM R16B PC2
Sources
euvd EUVD-2024-26983

Description

An authentication bypass vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway component that if exploited allows attackers without any access to interact with the services and the post-authentication attack surface.

References