PatchSiren cyber security CVE debrief
CVE-2024-28022 Hitachi Energy CVE debrief
CVE-2024-28022 affects Hitachi Energy UNEM server / APIGateway and allows a malicious user to make an arbitrary number of authentication attempts with different passwords until the targeted account is accessed. The advisory rates the issue CVSS 6.5 (Medium) and lists affected UNEM releases including R15A, R15B, R16A, R16B, and versions older than R15A.
- Vendor
- Hitachi Energy
- Product
- UNEM
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-06-11
- Original CVE updated
- 2024-10-29
- Advisory published
- 2024-06-11
- Advisory updated
- 2024-10-29
Who should care
Administrators and operators responsible for Hitachi Energy UNEM deployments, especially environments exposing the server or APIGateway to untrusted networks and sites running affected or end-of-life versions.
Technical summary
The CSAF advisory describes an authentication weakness in the UNEM server / APIGateway that permits repeated password attempts without effective restriction, enabling account access if the correct password is eventually tried. The advisory’s affected set includes UNEM R15A, R15B, R16A, R16B, and older-than-R15A versions. Remediation guidance differs by branch: update to UNEM R16B PC4 or R15B PC5 where applicable, and for EOL versions rely on general mitigation factors because no direct fix is planned.
Defensive priority
Medium
Recommended defensive actions
- Apply the vendor’s recommended update path where available: UNEM R16B PC4 or R15B PC5.
- For EOL releases, implement the vendor’s general mitigation factors and plan migration off unsupported versions.
- Restrict access to the UNEM server and APIGateway to trusted management networks only.
- Review authentication logs for repeated password attempts against targeted accounts.
- Follow CISA industrial control system defensive guidance for segmentation, least privilege, and defense in depth.
Evidence notes
The evidence corpus is a CISA CSAF security advisory for Hitachi Energy UNEM, with the same CVE identifier listed in the record and the vendor preview/reference links. The advisory states the impact, affected products, and remediation notes, including that some legacy versions have no direct remediation available. The provided enrichment shows no KEV listing and no ransomware campaign indicator.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-28022 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-28022
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-28022 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-28022
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-030-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-030-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.