Hitachi Energy

First CVE: Jul 14, 2021Active for: 5 years
111
CVEs Published
More CVEs Published than 71% of tracked CNAs
18.5
Avg CVEs / Year
More Avg CVEs / Year than 65% of tracked CNAs
7.0
Avg CVSS Score
Higher Avg CVSS Score than 45% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published by Hitachi Energy over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 14, 2021
5 years ago
Most Recent CVE
Jun 30, 2026
27 days ago

Top CVEs

All CVEs published by Hitachi Energy as a CNA, regardless of affected vendor or product.

111 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An authentication bypass vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway component that if exploited allows attackers without any access to interact with the servi
Jun 11, 202410.033NONO
vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway that if exploited an attacker could use to allow unintended commands or code to be executed on the UNEM server allo
Jun 11, 20249.833NONO
PROMOD V is using insecure HTTP communication instead of HTTPS. The vulnerability is due to the lack of HTTPS support from 3rd party Digipede server.
Jun 30, 20267.032NONO
A heap-based buffer overflow vulnerability exists in the FOXMAN-UN/UNEM that if exploited will generally lead to a denial of service but can be used to execute arbitrary code, whi
Jun 11, 20249.831NONO
The affected products store both public and private key that are used to sign and protect Custom Parameter Set (CPS) file from modification. An attacker that manages to exploit th
Jan 5, 20239.831NONO
A vulnerability exists in the query validation of the MicroSCADA Pro/X SYS600 product. If exploited this could allow an authenticated attacker to inject code towards persistent dat
Aug 27, 20248.830NONO
A vulnerability exists in a SDM600 endpoint. An attacker could exploit this vulnerability by running multiple parallel requests, the SDM600 web services become busy rendering the a
Mar 28, 20239.130NONO
Communication between the client and the server application of the affected products is partially done using CORBA (Common Object Request Broker Architecture) over TCP/IP. This pr
Jan 5, 20239.830NONO
In the DES implementation, the affected product versions use a default key for encryption. Successful exploitation allows an attacker to obtain sensitive information and gain acce
Jan 5, 20239.829NONO
IEC 60870-5-104 used in bidirectional mode in RTU500 is vulnerable for a NULL pointer dereferencing, if a specially crafted sequence of messages is sent for a certain time, causing
May 26, 20266.928NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA111 CVEs
Severity distribution among all CVEs352,785 CVEs
LowMediumHighCritical
Attack Vector
Local17 (15.3%)
Network88 (79.3%)
Unknown0 (0.0%)
Physical1 (0.9%)
Adjacent Network3 (2.7%)
Attack Complexity
Low99 (89.2%)
High12 (10.8%)
Unknown0 (0.0%)
User Interaction
None96 (86.5%)
Unknown0 (0.0%)
Required12 (10.8%)
Privileges Required
Low38 (34.2%)
High22 (19.8%)
None51 (45.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (111 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Hitachi Energy as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Hitachi Energy as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs