{
    "data_version": "4.0",
    "data_type": "CVE",
    "data_format": "MITRE",
    "CVE_data_meta": {
        "ID": "CVE-2021-40341",
        "ASSIGNER": "cybersecurity@hitachienergy.com",
        "STATE": "PUBLIC"
    },
    "description": {
        "description_data": [
            {
                "lang": "eng",
                "value": "DES cipher, which has inadequate encryption strength, is used Hitachi Energy FOXMAN-UN to encrypt user credentials used to access the Network Elements. Successful exploitation allows sensitive information to be decrypted easily. This issue affects * FOXMAN-UN product: FOXMAN-UN R16A, FOXMAN-UN R15B, FOXMAN-UN R15A, FOXMAN-UN R14B, FOXMAN-UN R14A, FOXMAN-UN R11B, FOXMAN-UN R11A, FOXMAN-UN R10C, FOXMAN-UN R9C; * UNEM product: UNEM R16A, UNEM R15B, UNEM R15A, UNEM R14B, UNEM R14A, UNEM R11B, UNEM R11A, UNEM R10C, UNEM R9C. List of CPEs: * cpe:2.3:a:hitachienergy:foxman-un:R16A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R15B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R15A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R14B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R14A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R11B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R11A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R10C:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R9C:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:unem:R16A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:unem:R15B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:unem:R15A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:unem:R14B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:unem:R14A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:unem:R11B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:unem:R11A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:unem:R10C:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:unem:R9C:*:*:*:*:*:*:*"
            }
        ]
    },
    "problemtype": {
        "problemtype_data": [
            {
                "description": [
                    {
                        "lang": "eng",
                        "value": "CWE-326 Inadequate Encryption Strength",
                        "cweId": "CWE-326"
                    }
                ]
            }
        ]
    },
    "affects": {
        "vendor": {
            "vendor_data": [
                {
                    "vendor_name": "Hitachi Energy",
                    "product": {
                        "product_data": [
                            {
                                "product_name": "FOXMAN-UN",
                                "version": {
                                    "version_data": [
                                        {
                                            "version_value": "FOXMAN-UN R16A",
                                            "version_affected": "="
                                        },
                                        {
                                            "version_value": "FOXMAN-UN R15B",
                                            "version_affected": "="
                                        },
                                        {
                                            "version_value": "FOXMAN-UN R15A",
                                            "version_affected": "="
                                        },
                                        {
                                            "version_value": "FOXMAN-UN R14B",
                                            "version_affected": "="
                                        },
                                        {
                                            "version_value": "FOXMAN-UN R14A",
                                            "version_affected": "="
                                        },
                                        {
                                            "version_value": "FOXMAN-UN R11B",
                                            "version_affected": "="
                                        },
                                        {
                                            "version_value": "FOXMAN-UN R11A",
                                            "version_affected": "="
                                        },
                                        {
                                            "version_value": "FOXMAN-UN R10C",
                                            "version_affected": "="
                                        },
                                        {
                                            "version_value": "FOXMAN-UN R9C",
                                            "version_affected": "="
                                        }
                                    ]
                                }
                            },
                            {
                                "product_name": "UNEM",
                                "version": {
                                    "version_data": [
                                        {
                                            "version_value": "UNEM R16A",
                                            "version_affected": "="
                                        },
                                        {
                                            "version_value": "UNEM R15B",
                                            "version_affected": "="
                                        },
                                        {
                                            "version_value": "UNEM R15A",
                                            "version_affected": "="
                                        },
                                        {
                                            "version_value": "UNEM R14B",
                                            "version_affected": "="
                                        },
                                        {
                                            "version_value": "UNEM R14A",
                                            "version_affected": "="
                                        },
                                        {
                                            "version_value": "UNEM R11B",
                                            "version_affected": "="
                                        },
                                        {
                                            "version_value": "UNEM R11A",
                                            "version_affected": "="
                                        },
                                        {
                                            "version_value": "UNEM R10C",
                                            "version_affected": "="
                                        },
                                        {
                                            "version_value": "UNEM R9C",
                                            "version_affected": "="
                                        }
                                    ]
                                }
                            }
                        ]
                    }
                }
            ]
        }
    },
    "references": {
        "reference_data": [
            {
                "url": "https://search.abb.com/library/Download.aspx?DocumentID=8DBD000083&LanguageCode=en&DocumentPartId=&Action=Launch",
                "refsource": "MISC",
                "name": "https://search.abb.com/library/Download.aspx?DocumentID=8DBD000083&LanguageCode=en&DocumentPartId=&Action=Launch"
            },
            {
                "url": "https://search.abb.com/library/Download.aspx?DocumentID=8DBD000084&LanguageCode=en&DocumentPartId=&Action=Launch",
                "refsource": "MISC",
                "name": "https://search.abb.com/library/Download.aspx?DocumentID=8DBD000084&LanguageCode=en&DocumentPartId=&Action=Launch"
            }
        ]
    },
    "generator": {
        "engine": "Vulnogram 0.1.0-dev"
    },
    "source": {
        "discovery": "EXTERNAL"
    },
    "work_around": [
        {
            "lang": "en",
            "supportingMedia": [
                {
                    "base64": false,
                    "type": "text/html",
                    "value": "\n\nThe vulnerabilities are partially remediated in FOXMAN-UN R16A or UNEM R16A, the full remediation will be done in the upcoming release (planned).\n<br><br>For immediate recommended mitigation actions if using FOXMAN-UN R16A or UNEM R16A,\nplease refer to the \n\n<span style=\"background-color: rgb(255, 255, 255);\">Database contains credentials with weak encryption</span>\n\nclause of section Mitigation Factors/Workarounds\nin the respective products' advisory.\n<br><br>For immediate recommended mitigation actions if using FOXMAN-UN R15B or UNEM R15B and earlier, please refer to the multiple clauses of section Mitigation Factors/Workarounds in the advisory<br><ul><li>Secure the NMS CLIENT/SERVER communication.&nbsp;</li><li>Embedded FOXCST with RADIUS authentication should be avoided.&nbsp;</li><li>Database contains credentials with weak encryption.\n\n</li></ul>"
                }
            ],
            "value": "\nThe vulnerabilities are partially remediated in FOXMAN-UN R16A or UNEM R16A, the full remediation will be done in the upcoming release (planned).\n\n\nFor immediate recommended mitigation actions if using FOXMAN-UN R16A or UNEM R16A,\nplease refer to the \n\nDatabase contains credentials with weak encryption\n\nclause of section Mitigation Factors/Workarounds\nin the respective products' advisory.\n\n\nFor immediate recommended mitigation actions if using FOXMAN-UN R15B or UNEM R15B and earlier, please refer to the multiple clauses of section Mitigation Factors/Workarounds in the advisory\n  *  Secure the NMS CLIENT/SERVER communication.\u00a0\n  *  Embedded FOXCST with RADIUS authentication should be avoided.\u00a0\n  *  Database contains credentials with weak encryption.\n\n\n\n\n"
        }
    ],
    "credits": [
        {
            "lang": "en",
            "value": "K-Businessom AG, Austria"
        }
    ],
    "impact": {
        "cvss": [
            {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "NONE",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
                "version": "3.1"
            }
        ]
    }
}