CVE-2022-3927

CRITICAL

The affected products store both public and private key that are used to sign and protect Custom Parameter Set (CPS) file from modification. An attacker that manages to exploit this vulnerability ...

Affects 2 products across 1 vendor.

BCS7.17
CVSS 3.19.8
EPSS0.6%
Percentile45th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-798: Use of Hard-Coded Credentials

Software contains embedded passwords or keys that cannot be changed by the administrator.

Related Attack Patterns (CAPEC)
CAPEC-70 Try Common or Default Usernames and Passwords
via CWE-798
CAPEC-191 Read Sensitive Constants Within an Executable
via CWE-798

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ AI Analysis — automated analysis, not human-reviewed

CVE-2022-3927 affects the FOXMAN-UN product series, allowing an attacker to modify and sign the Custom Parameter Set (CPS) file, leading to potential unauthorized changes in system behavior.

BSID: BS-2023-GLOBAL-063010-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2022-3927?
CVE-2022-3927 affects the FOXMAN-UN product series, allowing an attacker to modify and sign the Custom Parameter Set (CPS) file, leading to potential unauthorized changes in system behavior.
What is the CVSS score for CVE-2022-3927?
CVE-2022-3927 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 0.6%.
Is CVE-2022-3927 actively exploited?
No confirmed active exploitation of CVE-2022-3927 as of 2026-09-25.
How do I remediate CVE-2022-3927?
Priority: IMMEDIATE. Advisory: https://search.abb.com/library/Download.aspx?DocumentID=8DBD000083&LanguageCode=en&DocumentPartId=&Action=Launch PSIRT: [email protected]
What systems are affected by CVE-2022-3927?
CVE-2022-3927 affects: Hitachienergy, Hitachienergy.
Vulnerability Details
CVE IDCVE-2022-3927
BSIDBS-2023-GLOBAL-063010-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2023-01-05
Last Modified2026-06-17
ICS Relevance70%
Weakness (CWE)
SourceNVD
Official Description

The affected products store both public and private key that are used to sign and protect Custom Parameter Set (CPS) file from modification. An attacker that manages to exploit this vulnerability will be able to change the CPS file, sign it so that it is trusted as the legitimate CPS file. This issue affects * FOXMAN-UN product: FOXMAN-UN R15B, FOXMAN-UN R15A, FOXMAN-UN R14B, FOXMAN-UN R14A, FOXMAN-UN R11B, FOXMAN-UN R11A, FOXMAN-UN R10C, FOXMAN-UN R9C; * UNEM product: UNEM R15B, UNEM R15A, UNEM R14B, UNEM R14A, UNEM R11B, UNEM R11A, UNEM R10C, UNEM R9C. List of CPEs: * cpe:2.3:a:hitachienergy:foxman-un:R15B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R15A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R14B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R14A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R11B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R11A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R10C:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman-un:R9C:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:unem:R15B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:unem:R15A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:unem:R14B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:unem:R14A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:unem:R11B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:unem:R11A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:unem:R10C:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:unem:R9C:*:*:*:*:*:*:*

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

An attacker can exploit this vulnerability by gaining access to the system where the FOXMAN-UN product is installed. They can then modify the CPS file and sign it with the stored private key, making the altered file appear legitimate to the system.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Hitachienergy Foxman-Un —
Hitachienergy Unem —
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: September 2026 | Threat Age: 1361 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
AI Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash5d1c2022514949ebd9281619e10a3477fbd8d246399c4b6fef9694ea9b9f0ff02935ab70834dc2d3733fc6da3930f4011239af3585fe094629cc0eae453b24f8
Related CVEs affecting Hitachienergy
CVE-2024-2013 10.0 An authentication bypass vulnerability exists in the FOXMAN-UN/UNEM server / ... CVE-2019-18253 10.0 An attacker could use specially crafted paths in a specific request to read o... CVE-2021-40342 9.8 In the DES implementation, the affected product versions use a default key f... CVE-2018-14805 9.8 ABB eSOMS version 6.0.2 may allow unauthorized access to the system when LDAP... CVE-2019-5620 9.8 ABB MicroSCADA Pro SYS600 version 9.3 suffers from an instance of CWE-306: Mi...
View all Hitachienergy CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Create a free account →