CVE-2021-40341
DES cipher, which has inadequate encryption strength, is used Hitachi Energy FOXMAN-UN to encrypt user credentials used to access the Network Elements. Successful exploitation allows sensitive information to be decrypted easily. This issue affects FOXMAN-UN product: FOXMAN-UN R16A, FOXMAN-UN R15B, FOXMAN-UN R15A, FOXMAN-UN R14B, FOXMAN-UN R14A, FOXMAN-UN R11B, FOXMAN-UN R11A, FOXMAN-UN R10C, FOXMAN-UN R9C; UNEM product: UNEM R16A, UNEM R15B, UNEM R15A, UNEM R14B, UNEM R14A, UNEM R11B, UNEM R11A, UNEM R10C, UNEM R9C. List of CPEs: cpe:2.3:a:hitachienergy:foxman-un:R16A::::::: cpe:2.3:a:hitachienergy:foxman-un:R15B::::::: cpe:2.3:a:hitachienergy:foxman-un:R15A::::::: cpe:2.3:a:hitachienergy:foxman-un:R14B::::::: cpe:2.3:a:hitachienergy:foxman-un:R14A::::::: cpe:2.3:a:hitachienergy:foxman-un:R11B::::::: cpe:2.3:a:hitachienergy:foxman-un:R11A::::::: cpe:2.3:a:hitachienergy:foxman-un:R10C::::::: cpe:2.3:a:hitachienergy:foxman-un:R9C::::::: cpe:2.3:a:hitachienergy:unem:R16A::::::: cpe:2.3:a:hitachienergy:unem:R15B::::::: cpe:2.3:a:hitachienergy:unem:R15A::::::: cpe:2.3:a:hitachienergy:unem:R14B::::::: cpe:2.3:a:hitachienergy:unem:R14A::::::: cpe:2.3:a:hitachienergy:unem:R11B::::::: cpe:2.3:a:hitachienergy:unem:R11A::::::: cpe:2.3:a:hitachienergy:unem:R10C::::::: cpe:2.3:a:hitachienergy:unem:R9C:::::::.
- CVSS base score ≥ 7.0
ATT&CK techniques
1Techniques this CVE enables - linked via CWECAPECATT&CK. High◆ = named directly in ATT&CK or Nuclei templates.
▤ Build a SIEM detection for these techniquesCAPEC attack patterns
3Attack patterns this CVE enables - the bridge from weakness to ATT&CK technique.