# CVE-2024-28020

## Summary

- **CVE ID:** CVE-2024-28020
- **Severity:** HIGH
- **CVSS Score:** 8 (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** CWE-286
- **Published:** Jun 11, 2024
- **Last Modified:** Mar 13, 2026

## Description

A user/password reuse vulnerability exists in the FOXMAN-UN/UNEM application
and server management. If exploited a malicious high-privileged
user could use the passwords and login information through complex routines to extend access on the server and other services.

## Affected Products

- Hitachi Energy — FOXMAN-UN (FOXMAN-UN R16B)
- Hitachi Energy — FOXMAN-UN (FOXMAN-UN R15B)
- Hitachi Energy — FOXMAN-UN (FOXMAN-UN R16A)
- Hitachi Energy — FOXMAN-UN (FOXMAN-UN R15A)
- Hitachi Energy — UNEM (UNEM R16B)
- Hitachi Energy — UNEM (UNEM R15B)
- Hitachi Energy — UNEM (UNEM R16A)
- Hitachi Energy — UNEM (UNEM R15A)

## References

- [CNA](https://publisher.hitachienergy.com/preview?DocumentId=8DBD000194&languageCode=en&Preview=true)
- [CNA](https://publisher.hitachienergy.com/preview?DocumentId=8DBD000201&languageCode=en&Preview=true)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.37%
- **EPSS Percentile:** 30.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._