Hitachi Energy
First CVE: Jul 14, 2021Active for: 5 years
111
CVEs Published
More CVEs Published than 71% of tracked CNAs
18.5
Avg CVEs / Year
More Avg CVEs / Year than 65% of tracked CNAs
7.0
Avg CVSS Score
Higher Avg CVSS Score than 45% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by Hitachi Energy over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 14, 2021
5 years ago
Most Recent CVE
Jun 30, 2026
27 days ago
Top CVEs
All CVEs published by Hitachi Energy as a CNA, regardless of affected vendor or product.
111 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-2013CRITICAL An authentication bypass vulnerability exists in the FOXMAN-UN/UNEM server /
API Gateway component that if exploited allows attackers without
any access to interact with the servi | Jun 11, 2024 | 10.0 | 33 | NO | NO |
CVE-2024-2012CRITICAL vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway that if exploited an attacker could use to allow unintended commands or
code to be executed on the UNEM server allo | Jun 11, 2024 | 9.8 | 33 | NO | NO |
CVE-2026-10763HIGH PROMOD V is using insecure HTTP communication instead of HTTPS. The vulnerability is due to the lack of HTTPS support from 3rd party Digipede server. | Jun 30, 2026 | 7.0 | 32 | NO | NO |
CVE-2024-2011CRITICAL A heap-based buffer overflow vulnerability exists in the FOXMAN-UN/UNEM that
if exploited will generally lead to a denial of service but can be used
to execute arbitrary code, whi | Jun 11, 2024 | 9.8 | 31 | NO | NO |
CVE-2022-3927CRITICAL
The affected products store both public and private key that are used to sign and
protect Custom Parameter Set (CPS) file from modification. An attacker that manages to exploit th | Jan 5, 2023 | 9.8 | 31 | NO | NO |
CVE-2024-4872HIGH A vulnerability exists in the query validation of the MicroSCADA Pro/X SYS600 product. If exploited this could allow an authenticated attacker to inject code towards persistent dat | Aug 27, 2024 | 8.8 | 30 | NO | NO |
CVE-2022-3686CRITICAL A vulnerability exists in a SDM600 endpoint.
An attacker could exploit this vulnerability by running multiple parallel requests, the SDM600 web services become busy rendering the a | Mar 28, 2023 | 9.1 | 30 | NO | NO |
CVE-2022-3929CRITICAL
Communication between the client and the server application of the affected products is partially done using CORBA (Common Object Request Broker Architecture) over TCP/IP. This pr | Jan 5, 2023 | 9.8 | 30 | NO | NO |
CVE-2021-40342CRITICAL
In the DES implementation, the affected product versions use a default key for encryption. Successful exploitation allows an attacker to obtain sensitive information and gain acce | Jan 5, 2023 | 9.8 | 29 | NO | NO |
CVE-2026-8479MEDIUM IEC 60870-5-104 used in bidirectional mode in RTU500 is vulnerable
for a NULL pointer dereferencing, if a specially crafted
sequence of messages is sent for a certain time, causing | May 26, 2026 | 6.9 | 28 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA111 CVEs
41%
51%
Severity distribution among all CVEs352,785 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local17 (15.3%)
Network88 (79.3%)
Unknown0 (0.0%)
Physical1 (0.9%)
Adjacent Network3 (2.7%)
Attack Complexity
Low99 (89.2%)
High12 (10.8%)
Unknown0 (0.0%)
User Interaction
None96 (86.5%)
Unknown0 (0.0%)
Required12 (10.8%)
Privileges Required
Low38 (34.2%)
High22 (19.8%)
None51 (45.9%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (111 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Hitachi Energy as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Hitachi Energy as a CNA — matched by CVE ID, not by organization name.