Use of default key for encryption
CVE-2021-40342

7.1HIGH

Key Information:

Vendor
Hitachi
Vendor
CVE Published:
5 January 2023

Summary

A vulnerability exists in the DES implementation of Hitachi Energy's FOXMAN-UN and UNEM products, where a default key is used for encryption. This flaw could allow attackers to exploit the system to gain access to sensitive information and potentially compromise network elements managed by the affected products.

Affected Version(s)

FOXMAN-UN FOXMAN-UN R16A

FOXMAN-UN FOXMAN-UN R15B

FOXMAN-UN FOXMAN-UN R15A

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database

Credit

K-Businessom AG, Austria
.