High
CVE-2022-2155 CVSS:5.7
Hitachi Energy Lumada APM could allow a remote authenticated attacker to bypass security restrictions, caused by a flaw in the access control mechanism implementation on the Limited Engineer role. By sending a specially crafted request, an attacker could exploit this vulnerability to access to any installed Power BI reports and manipulate asset data.
CVE-2022-3929 CVSS:8.3
Hitachi Energy FOXMAN-UN and UNEM could allow a local attacker to obtain sensitive information, caused by cleartext transmission of sensitive information. A local attacker could exploit this vulnerability to obtain sensitive information.
CVE-2021-40342 CVSS:7.1
Hitachi Energy FOXMAN-UN and UNEM could allow a local attacker to obtain sensitive information, caused by using a DES implementation with a default key for encryption. A local attacker could exploit this vulnerability to obtain sensitive information.
CVE-2021-40341 CVSS:7.1
Hitachi Energy FOXMAN-UN and UNEM could allow a local attacker to obtain sensitive information, caused by using the DES cypher to encrypt user credentials. A local attacker could exploit this vulnerability to obtain sensitive information.
CVE-2022-3927 CVSS:8
Hitachi Energy FOXMAN-UN and UNEM could provide weaker than expected security, caused by the use of hard-coded cryptographic Key. A remote authenticated attacker could exploit this vulnerability to change the CPS file and sign it.
Hitachi Energy
Refer to Hitachi Energy Advisory for patch, upgrade or suggested workaround information.