Foxman-un
This hub aggregates every CVE we track for Foxman-un, a product in the ics ot iot space. Use it to gauge the current risk picture and drill into individual advisories.
15
CVEs tracked
2
Critical
8
High
0
In CISA KEV
Severity distribution
HIGH8MEDIUM5CRITICAL2
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Foxman-un.
- CVE-2024-28020A user/password reuse vulnerability exists in the FOXMAN-UN/UNEM application and server management. If exploited a malicious high-privileged user could use the passwords and login information throu...8.0
- CVE-2024-28024A vulnerability exists in the FOXMAN-UN/UNEM in which sensitive information is stored in cleartext within a resource that might be accessible to another control sphere.4.1
- CVE-2024-28022A vulnerability exists in the UNEM server / APIGateway that if exploited allows a malicious user to perform an arbitrary number of authentication attempts using different passwords, and eventually ...6.5
- CVE-2024-28023A vulnerability exists in the message queueing mechanism that if exploited can lead to the exposure of resources or functionality to unintended actors, possibly providing attackers with sensitive...5.7
- CVE-2024-28021A vulnerability exists in the FOXMAN-UN/UNEM server that affects the message queueing mechanism’s certificate validation. If exploited an attacker could spoof a trusted entity causing a loss of ...7.4
- CVE-2024-2011A heap-based buffer overflow vulnerability exists in the FOXMAN-UN/UNEM that if exploited will generally lead to a denial of service but can be used to execute arbitrary code, which is usually out...8.6
- CVE-2024-2012vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway that if exploited an attacker could use to allow unintended commands or code to be executed on the UNEM server allowing sensitive da...9.1
- CVE-2024-2013An authentication bypass vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway component that if exploited allows attackers without any access to interact with the services and the post-...10.0
- CVE-2024-2462Allow attackers to intercept or falsify data exchanges between the client and the server4.9
- CVE-2023-1711A vulnerability exists in a FOXMAN-UN and UNEM logging component, it only affects systems that use remote authentication to the network elements. If exploited an attacker could obtain confidential...4.0
- CVE-2022-3929Communication between the client and server partially using CORBA over TCP/IP8.3
- CVE-2022-3928Hardcoded credential is found in the message queue7.1
- CVE-2022-3927The affected products store public and private key that are used to sign and protect custom parameter set files from modification.8.0
- CVE-2021-40342Use of default key for encryption7.1
- CVE-2021-40341Weak DES encryption7.1
Product normalization is registry-driven with AI assist and human review. How it works