PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-28022 Hitachi Energy CVE debrief

CVE-2024-28022 affects Hitachi Energy UNEM server / APIGateway and allows a malicious user to make an arbitrary number of authentication attempts with different passwords until the targeted account is accessed. The advisory rates the issue CVSS 6.5 (Medium) and lists affected UNEM releases including R15A, R15B, R16A, R16B, and versions older than R15A.

Vendor
Hitachi Energy
Product
UNEM
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2024-06-11
Original CVE updated
2024-10-29
Advisory published
2024-06-11
Advisory updated
2024-10-29

Who should care

Administrators and operators responsible for Hitachi Energy UNEM deployments, especially environments exposing the server or APIGateway to untrusted networks and sites running affected or end-of-life versions.

Technical summary

The CSAF advisory describes an authentication weakness in the UNEM server / APIGateway that permits repeated password attempts without effective restriction, enabling account access if the correct password is eventually tried. The advisory’s affected set includes UNEM R15A, R15B, R16A, R16B, and older-than-R15A versions. Remediation guidance differs by branch: update to UNEM R16B PC4 or R15B PC5 where applicable, and for EOL versions rely on general mitigation factors because no direct fix is planned.

Defensive priority

Medium

Recommended defensive actions

  • Apply the vendor’s recommended update path where available: UNEM R16B PC4 or R15B PC5.
  • For EOL releases, implement the vendor’s general mitigation factors and plan migration off unsupported versions.
  • Restrict access to the UNEM server and APIGateway to trusted management networks only.
  • Review authentication logs for repeated password attempts against targeted accounts.
  • Follow CISA industrial control system defensive guidance for segmentation, least privilege, and defense in depth.

Evidence notes

The evidence corpus is a CISA CSAF security advisory for Hitachi Energy UNEM, with the same CVE identifier listed in the record and the vendor preview/reference links. The advisory states the impact, affected products, and remediation notes, including that some legacy versions have no direct remediation available. The provided enrichment shows no KEV listing and no ransomware campaign indicator.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-28022 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-28022

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-28022 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-28022

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-030-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-030-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.