Use of default key for encryption
CVE-2021-40342
7.1HIGH
Summary
A vulnerability exists in the DES implementation of Hitachi Energy's FOXMAN-UN and UNEM products, where a default key is used for encryption. This flaw could allow attackers to exploit the system to gain access to sensitive information and potentially compromise network elements managed by the affected products.
Affected Version(s)
FOXMAN-UN FOXMAN-UN R16A
FOXMAN-UN FOXMAN-UN R15B
FOXMAN-UN FOXMAN-UN R15A
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database
Credit
K-Businessom AG, Austria