Hitachi Energy FOXMAN-UN and UNEM Products
Hitachi Energy FOXMAN-UN and UNEM products versions R16A through R9C contain an information disclosure vulnerability that could allow an attacker with local access and administrative credentials to read sensitive configuration or credential information. The vulnerability exists in improper logging or information handling mechanisms (CWE-117). FOXMAN-UN R16A and UNEM R16A have fixes available in upcoming R16B releases; all other versions (R15B and earlier) are end-of-life with no planned patches. Affected products are used for electrical network management and substation automation in energy infrastructure.
- Physical access to the device
- High-privilege user account (administrative credentials)
- Ability to interact with the device interface or file system
- The device must be powered on and operational
Patching may require device reboot — plan for process interruption
/api/v1/advisories/1b45c663-7462-4d14-9c88-2c0c1a6ca208Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.