CVE-2021-40342
Last modified
CVE-2021-40342 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. In the DES implementation, the affected product versions use a default key for encryption. Successful exploitation allows an attacker to obtain sensitive information and gain access to the network elements that are managed by the affected products versions. This issue affects * FOXMAN-UN product: FOXMAN-UN R16A, FOXMAN-UN R15B, FOXMAN-UN R15A, FOXMAN-UN R14B, FOXMAN-UN R14A, FOXMAN-UN R11B, FOXMAN-UN R11A, FOXMAN-UN R10C, FOXMAN-UN R9C; * UNEM product: UNEM R16A, UNEM R15B, UNEM R15A, UNEM R14B, UNEM R14A, UNEM R11B, UNEM R11A, UNEM R10C, UNEM R9C. List of CPEs: * cpe:2.3:a:hitachienergy:foxman-un:R16A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R15B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R15A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R14B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R14A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R11B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R11A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R10C:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R9C:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:unem:R16A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:unem:R15B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:unem:R15A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:unem:R14B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:unem:R14A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:unem:R11B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:unem:R11A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:unem:R10C:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:unem:R9C:*:*:*:*:*:*:* . EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
In the DES implementation, the affected product versions use a default key for encryption. Successful exploitation allows an attacker to obtain sensitive information and gain access to the network elements that are managed by the affected products versions. This issue affects * FOXMAN-UN product: FOXMAN-UN R16A, FOXMAN-UN R15B, FOXMAN-UN R15A, FOXMAN-UN R14B, FOXMAN-UN R14A, FOXMAN-UN R11B, FOXMAN-UN R11A, FOXMAN-UN R10C, FOXMAN-UN R9C; * UNEM product: UNEM R16A, UNEM R15B, UNEM R15A, UNEM R14B, UNEM R14A, UNEM R11B, UNEM R11A, UNEM R10C, UNEM R9C. List of CPEs: * cpe:2.3:a:hitachienergy:foxman-un:R16A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R15B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R15A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R14B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R14A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R11B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R11A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R10C:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R9C:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:unem:R16A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:unem:R15B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:unem:R15A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:unem:R14B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:unem:R14A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:unem:R11B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:unem:R11A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:unem:R10C:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:unem:R9C:*:*:*:*:*:*:*
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hitachienergy | Foxman-Un | r9c |
| Hitachienergy | Foxman-Un | r10c |
| Hitachienergy | Foxman-Un | r11a |
| Hitachienergy | Foxman-Un | r11b |
| Hitachienergy | Foxman-Un | r14a |
| Hitachienergy | Foxman-Un | r14b |
| Hitachienergy | Foxman-Un | r15a |
| Hitachienergy | Foxman-Un | r15b |
| Hitachienergy | Foxman-Un | r16a |
| Hitachienergy | Unem | r9c |
| Hitachienergy | Unem | r10c |
| Hitachienergy | Unem | r11a |
| Hitachienergy | Unem | r11b |
| Hitachienergy | Unem | r14a |
| Hitachienergy | Unem | r14b |
| Hitachienergy | Unem | r15a |
| Hitachienergy | Unem | r15b |
| Hitachienergy | Unem | r16a |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-40342?
How severe is CVE-2021-40342?
How do I fix CVE-2021-40342?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-40337Cross-site Scripting (XSS) vulnerability in Hitachi Energy L…5.4
- CVE-2021-40338Hitachi Energy LinkOne product, has a vulnerability due to a…5.3
- CVE-2021-40339Configuration vulnerability in Hitachi Energy LinkOne applic…7.5
- CVE-2021-4034A local privilege escalation vulnerability was found on polk…7.8
- CVE-2021-40340Information Exposure vulnerability in Hitachi Energy LinkOne…7.5
- CVE-2021-40341DES cipher, which has inadequate encryption strength, is use…5.5
- CVE-2021-40343An issue was discovered in Nagios XI 5.8.5. Insecure file pe…7.8
- CVE-2021-40344An issue was discovered in Nagios XI 5.8.5. In the Custom In…7.2
- CVE-2021-40345An issue was discovered in Nagios XI 5.8.5. In the Manage Da…7.2
- CVE-2021-40346An integer overflow exists in HAProxy 2.0 through 2.5 in htx…7.5
- CVE-2021-40347An issue was discovered in views/list.py in GNU Mailman Post…5.4
- CVE-2021-40348Spacewalk 2.10, and derivatives such as Uyuni 2021.08, allow…8.8
Are you affected by CVE-2021-40342?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
