VYPR

Vendor CVEs

Eaton

All CVEs

76 total · sorted by risk
  • CVE-2021-23284MedApr 18, 2022
    risk 0.37cvss 5.7epss 0.01

    Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) version 1.5.0plus205 and all prior versions are vulnerable to Stored Cross-site Scripting vulnerability. This issue affects: Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) all version…

  • CVE-2025-22493MedMar 5, 2025
    risk 0.36cvss 5.6epss 0.00

    Secure flag not set and SameSIte was set to Lax in the Foreseer Reporting Software (FRS). Absence of this secure flag could lead into the session cookie being transmitted over unencrypted HTTP connections. This security issue has been resolved in the latest version of FRS…

  • CVE-2024-31416MedSep 13, 2024
    risk 0.36cvss 5.6epss 0.00

    The Eaton Foreseer software provides multiple customizable input fields for the users to configure parameters in the tool like alarms, reports, etc. Some of these input fields were not checking the length and bounds of the entered value. The exploit of this security flaw by a…

  • CVE-2021-23288MedApr 1, 2022
    risk 0.36cvss 5.6epss 0.00

    The vulnerability exists due to insufficient validation of input from certain resources by the IPP software. The attacker would need access to the local Subnet and an administrator interaction to compromise the system. This issue affects: Intelligent Power Protector versions…

  • CVE-2021-23287MedApr 1, 2022
    risk 0.36cvss 5.6epss 0.00

    The vulnerability exists due to insufficient validation of input of certain resources within the IPM software. This issue affects: Intelligent Power Manager (IPM 1) versions prior to 1.70.

  • CVE-2020-10637MedApr 15, 2020
    risk 0.36cvss 5.5epss 0.01

    Eaton HMiSoft VU3 (HMIVU3 runtime not impacted), Version 3.00.23 and prior, however, the HMIVU runtimes are not impacted by these issues. A specially crafted input file could trigger an out-of-bounds read when loaded by the affected product.

  • CVE-2018-7511MedMar 20, 2018
    risk 0.35cvss 5.3epss 0.04

    In Eaton ELCSoft versions 2.04.02 and prior, there are multiple cases where specially crafted files could cause a buffer overflow which, in turn, may allow remote execution of arbitrary code.

  • CVE-2016-9357MedFeb 13, 2017
    risk 0.35cvss 5.3epss 0.02

    An issue was discovered in certain legacy Eaton ePDUs -- the affected products are past end-of-life (EoL) and no longer supported: EAMxxx prior to June 30, 2015, EMAxxx prior to January 31, 2014, EAMAxx prior to January 31, 2014, EMAAxx prior to January 31, 2014, and ESWAxx…

  • CVE-2015-6471MedDec 23, 2015
    risk 0.35cvss 5.3epss 0.01

    Eaton Cooper Power Systems ProView 4.x and 5.x before 5.1 on Form 6 controls and Idea and IdeaPLUS relays does not properly initialize padding fields in Ethernet packets, which allows remote attackers to obtain sensitive information by reading packet data.

  • CVE-2021-23282MedNov 25, 2024
    risk 0.34cvss 5.2epss 0.08

    Eaton Intelligent Power Manager (IPM) prior to 1.70 is vulnerable to stored Cross site scripting. The vulnerability exists due to insufficient validation of input from certain resources by the IPM software. The attacker would need access to the local Subnet and an administrator…

  • CVE-2021-23283MedApr 19, 2022
    risk 0.34cvss 5.2epss 0.01

    Eaton Intelligent Power Protector (IPP) prior to version 1.69 is vulnerable to stored Cross Site Scripting. The vulnerability exists due to insufficient validation of user input and improper encoding of the output for certain resources within the IPP software.

  • CVE-2022-33861MedNov 25, 2024
    risk 0.33cvss 5.1epss 0.00

    IPP software versions prior to v1.71 do not sufficiently verify the authenticity of data, in a way that causes it to accept invalid data.

  • CVE-2018-9280MedOct 24, 2018
    risk 0.32cvss 4.9epss 0.01

    An issue was discovered on Eaton UPS 9PX 8000 SP devices. The appliance discloses the SNMP version 3 user's password. The web page displayed by the appliance contains the password in cleartext. Passwords of the read and write users could be retrieved by browsing the source code…

  • CVE-2018-9279MedOct 24, 2018
    risk 0.32cvss 4.9epss 0.01

    An issue was discovered on Eaton UPS 9PX 8000 SP devices. The appliance discloses the user's password. The web page displayed by the appliance contains the password in cleartext. Passwords could be retrieved by browsing the source code of the webpage.

  • CVE-2025-48395MedSep 5, 2025
    risk 0.31cvss 4.7epss 0.00

    An attacker with authenticated and privileged access could modify the contents of a non-sensitive file by traversing the path in the limited shell of the CLI. This security issue has been fixed in the latest version of NMC G2 which is available on the Eaton download center.

  • CVE-2025-48394MedAug 6, 2025
    risk 0.31cvss 4.7epss 0.00

    An attacker with authenticated and privileged access could modify the contents of a non-sensitive file by traversing the path in the limited shell of the CLI. This security issue has been fixed in the latest version which is available on the Eaton download center.

  • CVE-2023-43775MedSep 27, 2023
    risk 0.31cvss 4.7epss 0.01

    Denial-of-service vulnerability in the web server of the Eaton SMP Gateway allows attacker to potentially force an unexpected restart of the automation platform, impacting the availability of the product. In rare situations, the issue could cause the SMP device to restart in…

  • CVE-2020-7915MedJan 22, 2020
    risk 0.31cvss 4.8epss 0.01

    An issue was discovered on Eaton 5P 850 devices. The Ubicacion SAI field allows XSS attacks by an administrator.

  • CVE-2020-6653LowAug 12, 2020
    risk 0.25cvss 3.8epss 0.00

    Eaton's Secure connect mobile app v1.7.3 & prior stores the user login credentials in logcat file when user create or register the account on the Mobile app. A malicious app or unauthorized user can harvest the information and later on can use the information to monitor and…

  • CVE-2021-23285LowApr 18, 2022
    risk 0.20cvss 3.1epss 0.00

    Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) version 1.5.0plus205 and all prior versions are vulnerable to reflected Cross-site Scripting vulnerability. This issue affects: Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) all version…

  • CVE-2026-22622HigJul 30, 2026
    risk 0.00cvss 8.8epss 0.00

    Improper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware could allow an authenticated user to elevate privileges resulting in unrestricted access to the device.

  • CVE-2026-22621HigJul 30, 2026
    risk 0.00cvss 8.3epss 0.00

    Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could allow an authenticated administrator to execute arbitrary commands within a restricted environment.

  • CVE-2026-22620HigJul 30, 2026
    risk 0.00cvss 8.6epss 0.00

    Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unauthenticated remote attacker to bypass authentication and gain a privileged user access to the device.

  • CVE-2014-9196Jul 20, 2015
    risk 0.00cvss —epss 0.02

    Eaton Cooper Power Systems ProView 4.0 and 5.0 before 5.0 11 on Form 6 controls and Idea and IdeaPLUS relays generates TCP initial sequence number (ISN) values linearly, which makes it easier for remote attackers to spoof TCP sessions by predicting an ISN value.

  • CVE-2013-2814Dec 17, 2013
    risk 0.00cvss —epss 0.01

    Cooper Power Systems Cybectec DNP3 Master OPC Server allows remote attackers to cause a denial of service (unhandled exception and process crash) via unspecified vectors.

  • CVE-2008-6816May 28, 2009
    risk 0.00cvss —epss 0.04

    Eaton MGEOPS Network Shutdown Module before 3.10 Build 13 allows remote attackers to execute arbitrary code by adding a custom action to the MGE frontend via pane_actionbutton.php, and then executing this action via exec_action.php.

Page 2 of 2