VYPR

Vendor CVEs

Eaton

All CVEs

76 total · sorted by risk
  • CVE-2018-16158CriAug 30, 2018
    risk 0.69cvss 9.8epss 0.35

    Eaton Power Xpert Meter 4000, 6000, and 8000 devices before 13.4.0.10 have a single SSH private key across different customers' installations and do not properly restrict access to this key, which makes it easier for remote attackers to perform SSH logins (to uid 0) via the…

  • CVE-2021-23281CriApr 13, 2021
    risk 0.65cvss 10.0epss 0.02

    Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated remote code execution vulnerability. IPM software does not sanitize the date provided via coverterCheckList action in meta_driver_srv.js class. Attackers can send a specially crafted packet to…

  • CVE-2018-12031CriJun 7, 2018
    risk 0.65cvss 9.8epss 0.17

    Local file inclusion in Eaton Intelligent Power Manager v1.6 allows an attacker to include a file via server/node_upgrade_srv.js directory traversal with the firmware parameter in a downloadFirmware action.

  • CVE-2018-8847CriJul 13, 2018
    risk 0.64cvss 9.8epss 0.07

    Eaton 9000X DriveA versions 2.0.29 and prior has a stack-based buffer overflow vulnerability, which may allow remote code execution.

  • CVE-2024-57811CriJan 13, 2025
    risk 0.59cvss 9.1epss 0.00

    In Eaton X303 3.5.16 - X303 3.5.17 Build 712, an attacker with network access to a XC-303 PLC can login as root over SSH. The root password is hardcoded in the firmware. NOTE: This vulnerability appears in versions that are no longer supported by Eaton.

  • CVE-2025-59886HigDec 23, 2025
    risk 0.57cvss 8.8epss 0.00

    Improper input validation at one of the endpoints of Eaton xComfort ECI's web interface, could lead into an attacker with network access to the device executing privileged user commands. As cybersecurity standards continue to evolve and to meet our requirements today, Eaton…

  • CVE-2021-23278HigApr 13, 2021
    risk 0.57cvss 8.7epss 0.01

    Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated arbitrary file delete vulnerability induced due to improper input validation at server/maps_srv.js with action removeBackground and server/node_upgrade_srv.js with action removeFirmware. An…

  • CVE-2020-6651HigMay 7, 2020
    risk 0.57cvss 8.8epss 0.02

    Improper Input Validation in Eaton's Intelligent Power Manager (IPM) v 1.67 & prior on file name during configuration file import functionality allows attackers to perform command injection or code execution via specially crafted file names while uploading the configuration file…

  • CVE-2018-9281HigOct 24, 2018
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered on Eaton UPS 9PX 8000 SP devices. The administration panel is vulnerable to a CSRF attack on the change-password functionality. This vulnerability could be used to force a logged-in administrator to perform a silent password update. The affected forms are…

  • CVE-2025-59887HigDec 26, 2025
    risk 0.56cvss 8.6epss 0.00

    Improper authentication of library files in the Eaton UPS Companion software installer could lead to arbitrary code execution of an attacker with the access to the software package. This security issue has been fixed in the latest version of EUC which is available on the Eaton…

  • CVE-2025-59889HigOct 14, 2025
    risk 0.56cvss 8.6epss 0.00

    Improper authentication of library files in the Eaton IPP software installer could lead to arbitrary code execution of an attacker with the access to the software package.  This security issue has been fixed in the latest version of IPP which is available on the Eaton download…

  • CVE-2025-22495HigFeb 24, 2025
    risk 0.55cvss 8.4epss 0.00

    An improper input validation vulnerability was discovered in the NTP server configuration field of the Network-M2 card. This could result in an authenticated high privileged user having the ability to execute arbitrary commands. The vulnerability has been resolved in the version…

  • CVE-2025-48396HigNov 3, 2025
    risk 0.54cvss 8.3epss 0.00

    Arbitrary code execution is possible due to improper validation of the file upload functionality in Eaton BLSS. This security issue has been fixed in the latest script patch latest version of of Eaton BLSS (7.3.0.SCP004).

  • CVE-2021-23279HigApr 13, 2021
    risk 0.54cvss 8.0epss 0.27

    Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated arbitrary file delete vulnerability induced due to improper input validation in meta_driver_srv.js class with saveDriverData action using invalidated driverID. An attacker can send specially…

  • CVE-2021-23277HigApr 13, 2021
    risk 0.54cvss 8.3epss 0.01

    Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated eval injection vulnerability. The software does not neutralize code syntax from users before using in the dynamic evaluation call in loadUserFile function under scripts/libs/utils.js. Successful…

  • CVE-2020-6650HigMar 23, 2020
    risk 0.54cvss 8.3epss 0.02

    UPS companion software v1.05 & Prior is affected by ‘Eval Injection’ vulnerability. The software does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call e.g.”eval” in “Update Manager” class when software attempts…

  • CVE-2022-33859HigOct 28, 2022
    risk 0.53cvss 8.1epss 0.00

    A security vulnerability was discovered in the Eaton Foreseer EPMS software. Foreseer EPMS connects an operation’s vast array of devices to assist in the reduction of energy consumption and avoid unplanned downtime caused by the failures of critical systems. A threat actor may…

  • CVE-2021-23280HigApr 13, 2021
    risk 0.52cvss 8.0epss 0.01

    Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated arbitrary file upload vulnerability. IPM’s maps_srv.js allows an attacker to upload a malicious NodeJS file using uploadBackgroud action. An attacker can upload a malicious code or execute any…

  • CVE-2026-22619HigApr 16, 2026
    risk 0.51cvss 7.8epss 0.00

    Eaton Intelligent Power Protector (IPP) is affected by insecure library loading in its executable, which could lead to arbitrary code execution by an attacker with access to the software package. This security issue has been fixed in the latest version of Eaton IPP software…

  • CVE-2025-67450HigDec 26, 2025
    risk 0.51cvss 7.8epss 0.00

    Due to insecure library loading in the Eaton UPS Companion software executable, an attacker with access to the software package could perform arbitrary code execution . This security issue has been fixed in the latest version of EUC which is available on the Eaton download…

  • CVE-2021-22663HigFeb 9, 2021
    risk 0.51cvss 7.8epss 0.01

    Cscape (All versions prior to 9.90 SP3.5) lacks proper validation of user-supplied data when parsing project files. This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to execute code in the context of the current process.

  • CVE-2020-6654HigSep 30, 2020
    risk 0.51cvss 7.8epss 0.00

    A DLL Hijacking vulnerability in Eaton's 9000x Programming and Configuration Software v 2.0.38 and prior allows an attacker to execute arbitrary code by replacing the required DLLs with malicious DLLs when the software try to load vci11un6.DLL and cinpl.DLL.

  • CVE-2020-6652HigMay 7, 2020
    risk 0.51cvss 7.8epss 0.00

    Incorrect Privilege Assignment vulnerability in Eaton's Intelligent Power Manager (IPM) v1.67 & prior allow non-admin users to upload the system configuration files by sending specially crafted requests. This can result in non-admin users manipulating the system configurations…

  • CVE-2020-10639HigApr 15, 2020
    risk 0.51cvss 7.8epss 0.01

    Eaton HMiSoft VU3 (HMIVU3 runtime not impacted), Version 3.00.23 and prior, however, the HMIVU runtimes are not impacted by these issues. A specially crafted input file could cause a buffer overflow when loaded by the affected product.

  • CVE-2016-9368HigMar 14, 2017
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Eaton xComfort Ethernet Communication Interface (ECI) Versions 1.07 and prior. By accessing a specific uniform resource locator (URL) on the webserver, a malicious user may be able to access files without authenticating.

  • CVE-2016-2272HigApr 6, 2016
    risk 0.49cvss 7.5epss 0.01

    Eaton Lighting EG2 Web Control 4.04P and earlier allows remote attackers to have an unspecified impact via a modified cookie.

  • CVE-2016-0871HigApr 6, 2016
    risk 0.49cvss 7.5epss 0.02

    Eaton Lighting EG2 Web Control 4.04P and earlier allows remote attackers to read the configuration file, and consequently discover credentials, via a direct request.

  • CVE-2016-4512HigJul 3, 2016
    risk 0.48cvss 7.3epss 0.04

    Stack-based buffer overflow in ELCSimulator in Eaton ELCSoft 2.4.01 and earlier allows remote attackers to execute arbitrary code via a long packet.

  • CVE-2025-59890HigNov 27, 2025
    risk 0.47cvss 7.3epss 0.00

    Improper input sanitization in the file archives upload functionality of Eaton Galileo software allows traversing paths which could lead into an attacker with local access to execute unauthorized code or commands. This security issue has been fixed in the latest version of…

  • CVE-2025-48397HigNov 3, 2025
    risk 0.46cvss 7.1epss 0.00

    The privileged user could log in without sufficient credentials after enabling an application protocol. This security issue has been fixed in the latest script patch latest version of of Eaton BLSS (7.3.0.SCP004).

  • CVE-2021-23276HigApr 13, 2021
    risk 0.46cvss 7.1epss 0.01

    Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated SQL injection. A malicious user can send a specially crafted packet to exploit the vulnerability. Successful exploitation of this vulnerability can allow attackers to add users in the data base.

  • CVE-2019-5625HigMay 22, 2019
    risk 0.46cvss 7.1epss 0.00

    The Android mobile application Halo Home before 1.11.0 stores OAuth authentication and refresh access tokens in a clear text file. This file persists until the user logs out of the application and reboots the device. This vulnerability can allow an attacker to impersonate the…

  • CVE-2025-59888MedDec 26, 2025
    risk 0.44cvss 6.7epss 0.00

    Improper quotation in search paths in the Eaton UPS Companion software installer could lead to arbitrary code execution of an attacker with the access to the file system. This security issue has been fixed in the latest version of EUC which is available on the Eaton download…

  • CVE-2025-22491MedFeb 28, 2025
    risk 0.44cvss 6.7epss 0.00

    The user input was not sanitized on Reporting Hierarchy Management page of Foreseer Reporting Software (FRS) application which could lead into execution of arbitrary JavaScript in a browser context for all the interacting users. This security issue has been patched in the latest…

  • CVE-2022-33862MedNov 25, 2024
    risk 0.44cvss 6.7epss 0.00

    IPP software prior to v1.71 is vulnerable to default credential vulnerability. This could lead attackers to identify and access vulnerable systems.

  • CVE-2024-31414MedSep 13, 2024
    risk 0.44cvss 6.7epss 0.00

    The Eaton Foreseer software provides users the capability to customize the dashboard in WebView pages. However, the input fields for this feature in the Eaton Foreseer software lacked proper input sanitization on the server-side, which could lead to injection and execution of…

  • CVE-2023-43776MedOct 17, 2023
    risk 0.44cvss 6.8epss 0.00

    Eaton easyE4 PLC offers a device password protection functionality to facilitate a secure connection and prevent unauthorized access. It was observed that the device password was stored with a weak encoding algorithm in the easyE4 program file when exported to SD card (*.PRG…

  • CVE-2026-22616MedApr 16, 2026
    risk 0.42cvss 6.5epss 0.00

    Eaton Intelligent Power Protector (IPP) software allows repeated authentication attempts against the web interface login page due to insufficient rate‑limiting controls. This security issue has been fixed in the latest version of Eaton IPP which is available on the Eaton…

  • CVE-2024-31415MedSep 13, 2024
    risk 0.41cvss 6.3epss 0.00

    The Eaton Foreseer software provides the feasibility for the user to configure external servers for multiple purposes such as network management, user management, etc. The software uses encryption to store these configurations securely on the host machine. However, the keys used…

  • CVE-2026-22614MedMar 10, 2026
    risk 0.40cvss 6.1epss 0.00

    The encryption mechanism used in Eaton's EasySoft project file was insecure and susceptible to brute force attacks, an attacker with access to this file and the local host machine could potentially read the sensitive information stored and tamper with the project file. This…

  • CVE-2026-22615MedApr 16, 2026
    risk 0.39cvss 6.0epss 0.00

    Due to improper input validation in one of the Eaton Intelligent Power Protector (IPP) XML, it is possible for an attacker with admin privileges and access to the local system to inject malicious code resulting in arbitrary command execution. This security issue has been fixed…

  • CVE-2016-4509MedJul 3, 2016
    risk 0.39cvss 6.0epss 0.02

    Heap-based buffer overflow in elcsoft.exe in Eaton ELCSoft 2.4.01 and earlier allows remote authenticated users to execute arbitrary code via a crafted file.

  • CVE-2026-22618MedApr 16, 2026
    risk 0.38cvss 5.9epss 0.00

    A security misconfiguration was identified in Eaton Intelligent Power Protector (IPP), where an HTTP response header was set with an insecure attribute, potentially exposing users to web‑based attacks. This security issue has been fixed in the latest version of Eaton IPP…

  • CVE-2023-43777MedOct 17, 2023
    risk 0.38cvss 5.9epss 0.00

    Eaton easySoft software is used to program easy controllers and displays for configuring, programming and defining parameters for all the intelligent relays. This software has a password protection functionality to secure the project file from unauthorized access. This password…

  • CVE-2020-6656MedJan 7, 2021
    risk 0.38cvss 5.8epss 0.03

    Eaton's easySoft software v7.xx prior to v7.22 are susceptible to file parsing type confusion remote code execution vulnerability. A malicious entity can execute a malicious code or make the application crash by tricking user upload a malformed .E70 file in the application. The…

  • CVE-2020-6655MedJan 7, 2021
    risk 0.38cvss 5.8epss 0.03

    The Eaton's easySoft software v7.xx prior to v7.22 are susceptible to Out-of-bounds remote code execution vulnerability. A malicious entity can execute a malicious code or make the application crash by tricking user to upload the malformed .E70 file in the application. The…

  • CVE-2026-22617MedApr 16, 2026
    risk 0.37cvss 5.7epss 0.00

    Eaton Intelligent Power Protector (IPP) uses an insecure cookie configuration, which could allow a network‑based attacker to intercept the cookie and exploit it through a man‑in‑the‑middle attack. This security issue has been fixed in the latest version of Eaton IPP…

  • CVE-2026-22613MedFeb 9, 2026
    risk 0.37cvss 5.7epss 0.00

    The server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potentially allowing an attacker to perform a Man-in-the-middle attack. This security issue has been fixed in the latest firmware version of Eaton Network M3 which…

  • CVE-2025-48393MedAug 6, 2025
    risk 0.37cvss 5.7epss 0.00

    The server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potentially allowing an attacker to perform a Man-in-the-middle attack. This security issue has been fixed in the latest firmware version of Eaton G4 PDU which is…

  • CVE-2021-23286MedApr 18, 2022
    risk 0.37cvss 5.7epss 0.00

    Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) version 1.5.0plus205 and all prior versions are vulnerable to CSV Formula Injection. This issue affects: Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) all version 1.5.0plus205 and prior…

Page 1 of 2