{ "data_version": "4.0", "data_type": "CVE", "data_format": "MITRE", "CVE_data_meta": { "ID": "CVE-2022-3929", "ASSIGNER": "cybersecurity@hitachienergy.com", "STATE": "PUBLIC" }, "description": { "description_data": [ { "lang": "eng", "value": "Communication between the client and the server application of the affected products is partially done using CORBA (Common Object Request Broker Architecture) over TCP/IP. This protocol is not encrypted and allows tracing of internal messages. This issue affects * FOXMAN-UN product: FOXMAN-UN R15B, FOXMAN-UN R15A, FOXMAN-UN R14B, FOXMAN-UN R14A, FOXMAN-UN R11B, FOXMAN-UN R11A, FOXMAN-UN R10C, FOXMAN-UN R9C; * UNEM product: UNEM R15B, UNEM R15A, UNEM R14B, UNEM R14A, UNEM R11B, UNEM R11A, UNEM R10C, UNEM R9C. List of CPEs: * cpe:2.3:a:hitachienergy:foxman-un:R15B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R15A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R14B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R14A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R11B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R11A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R10C:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R9C:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:unem:R15B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:unem:R15A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:unem:R14B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:unem:R14A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:unem:R11B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:unem:R11A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:unem:R10C:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:unem:R9C:*:*:*:*:*:*:*" } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "CWE-319 Cleartext Transmission of Sensitive Information", "cweId": "CWE-319" } ] } ] }, "affects": { "vendor": { "vendor_data": [ { "vendor_name": "Hitachi Energy", "product": { "product_data": [ { "product_name": "FOXMAN-UN", "version": { "version_data": [ { "version_value": "FOXMAN-UN R16A", "version_affected": "!" }, { "version_value": "FOXMAN-UN R15B", "version_affected": "=" }, { "version_value": "FOXMAN-UN R15A", "version_affected": "=" }, { "version_value": "FOXMAN-UN R14B", "version_affected": "=" }, { "version_value": "FOXMAN-UN R14A", "version_affected": "=" }, { "version_value": "FOXMAN-UN R11B", "version_affected": "=" }, { "version_value": "FOXMAN-UN R11A", "version_affected": "=" }, { "version_value": "FOXMAN-UN R10C", "version_affected": "=" }, { "version_value": "FOXMAN-UN R9C", "version_affected": "=" } ] } }, { "product_name": "UNEM", "version": { "version_data": [ { "version_value": "UNEM R16A", "version_affected": "!" }, { "version_value": "UNEM R15B", "version_affected": "=" }, { "version_value": "UNEM R15A", "version_affected": "=" }, { "version_value": "UNEM R14B", "version_affected": "=" }, { "version_value": "UNEM R14A", "version_affected": "=" }, { "version_value": "UNEM R11B", "version_affected": "=" }, { "version_value": "UNEM R11A", "version_affected": "=" }, { "version_value": "UNEM R10C", "version_affected": "=" }, { "version_value": "UNEM R9C", "version_affected": "=" } ] } } ] } } ] } }, "references": { "reference_data": [ { "url": "https://search.abb.com/library/Download.aspx?DocumentID=8DBD000083&LanguageCode=en&DocumentPartId=&Action=Launch", "refsource": "MISC", "name": "https://search.abb.com/library/Download.aspx?DocumentID=8DBD000083&LanguageCode=en&DocumentPartId=&Action=Launch" }, { "url": "https://search.abb.com/library/Download.aspx?DocumentID=8DBD000084&LanguageCode=en&DocumentPartId=&Action=Launch", "refsource": "MISC", "name": "https://search.abb.com/library/Download.aspx?DocumentID=8DBD000084&LanguageCode=en&DocumentPartId=&Action=Launch" } ] }, "generator": { "engine": "Vulnogram 0.1.0-dev" }, "source": { "discovery": "EXTERNAL" }, "work_around": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\n\nFor immediate recommended mitigation actions if using FOXMAN-UN R15B or UNEM R15B and earlier, please refer to the multiple clauses of section Mitigation Factors/Workarounds in the advisory
\n\n" } ], "value": "\nFor immediate recommended mitigation actions if using FOXMAN-UN R15B or UNEM R15B and earlier, please refer to the multiple clauses of section Mitigation Factors/Workarounds in the advisory\n * Secure the NMS CLIENT/SERVER communication.\n\n\n\n\n" } ], "credits": [ { "lang": "en", "value": "K-Businessom AG, Austria" } ], "impact": { "cvss": [ { "attackComplexity": "HIGH", "attackVector": "ADJACENT_NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.3, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "CHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H", "version": "3.1" } ] } }