← Back

Eaton

eaton

54 CVEs • 90 products

Products (90)

Click to collapse
Toggle
Ups Companion
ups_companion
Easysoft
easysoft
Elcsoft
elcsoft
Proview
proview
9000x Firmware
9000x_firmware
Halo Home
halo_home
Secureconnect
secureconnect
9000x
9px Ups
9px_ups
5p 850
5p_850
Hmisoft Vu3
hmisoft_vu3
Smp Sg 4260
smp_sg-4260
Smp Sg 4250
smp_sg-4250
Smp 4/dp
smp_4/dp
Smp 16
smp_16

CVEs (54)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Eaton
19px Ups Firmware
Jun 17, 2026
Oct 24, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered on Eaton UPS 9PX 8000 SP devices. The administration panel is vulnerable to a CSRF attack on the change-password functionality. This vulnerability could be used to force a logged-in administrator...Show more
An issue was discovered on Eaton UPS 9PX 8000 SP devices. The administration panel is vulnerable to a CSRF attack on the change-password functionality. This vulnerability could be used to force a logged-in administrator to perform a silent password update. The affected forms are also vulnerable to Reflected Cross-Site Scripting vulnerabilities. This flaw could be triggered by driving an administrator logged into the Eaton application to a specially crafted web page. This attack could be done silently.Show less
1Eaton
19px Ups Firmware
Jun 17, 2026
Oct 24, 2018
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered on Eaton UPS 9PX 8000 SP devices. The appliance discloses the SNMP version 3 user's password. The web page displayed by the appliance contains the password in cleartext. Passwords of the read and...Show more
An issue was discovered on Eaton UPS 9PX 8000 SP devices. The appliance discloses the SNMP version 3 user's password. The web page displayed by the appliance contains the password in cleartext. Passwords of the read and write users could be retrieved by browsing the source code of the webpage.Show less
1Eaton
19px Ups Firmware
Jun 17, 2026
Oct 24, 2018
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered on Eaton UPS 9PX 8000 SP devices. The appliance discloses the user's password. The web page displayed by the appliance contains the password in cleartext. Passwords could be retrieved by browsing...Show more
An issue was discovered on Eaton UPS 9PX 8000 SP devices. The appliance discloses the user's password. The web page displayed by the appliance contains the password in cleartext. Passwords could be retrieved by browsing the source code of the webpage.Show less
1Eaton
3Power Xpert Meter 4000 Firmware
Power Xpert Meter 6000 FirmwarePower Xpert Meter 8000 Firmware
Nov 21, 2024
Aug 30, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Eaton Power Xpert Meter 4000, 6000, and 8000 devices before 13.4.0.10 have a single SSH private key across different customers' installations and do not properly restrict access to this key, which makes it easier for rem...Show more
Eaton Power Xpert Meter 4000, 6000, and 8000 devices before 13.4.0.10 have a single SSH private key across different customers' installations and do not properly restrict access to this key, which makes it easier for remote attackers to perform SSH logins (to uid 0) via the PubkeyAuthentication option.Show less
1Eaton
19000x Firmware
Jun 17, 2026
Jul 13, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Eaton 9000X DriveA versions 2.0.29 and prior has a stack-based buffer overflow vulnerability, which may allow remote code execution.
1Eaton
1Intelligent Power Manager
Nov 21, 2024
Jun 7, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Local file inclusion in Eaton Intelligent Power Manager v1.6 allows an attacker to include a file via server/node_upgrade_srv.js directory traversal with the firmware parameter in a downloadFirmware action.
1Eaton
1Elcsoft
Jun 17, 2026
Mar 20, 2018
N/A· v4
5.3 MEDIUM· v3
6.8 MEDIUM· v2
In Eaton ELCSoft versions 2.04.02 and prior, there are multiple cases where specially crafted files could cause a buffer overflow which, in turn, may allow remote execution of arbitrary code.
1Eaton
1Xcomfort Ethernet Communication Interface
May 13, 2026
Mar 14, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Eaton xComfort Ethernet Communication Interface (ECI) Versions 1.07 and prior. By accessing a specific uniform resource locator (URL) on the webserver, a malicious user may be able to access fi...Show more
An issue was discovered in Eaton xComfort Ethernet Communication Interface (ECI) Versions 1.07 and prior. By accessing a specific uniform resource locator (URL) on the webserver, a malicious user may be able to access files without authenticating.Show less
1Eaton
5Eamaxx Series Epdu Firmware
Eamxxx Series Epdu FirmwareEmaaxx Series Epdu Firmware+2 more
May 13, 2026
Feb 13, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in certain legacy Eaton ePDUs -- the affected products are past end-of-life (EoL) and no longer supported: EAMxxx prior to June 30, 2015, EMAxxx prior to January 31, 2014, EAMAxx prior to January...Show more
An issue was discovered in certain legacy Eaton ePDUs -- the affected products are past end-of-life (EoL) and no longer supported: EAMxxx prior to June 30, 2015, EMAxxx prior to January 31, 2014, EAMAxx prior to January 31, 2014, EMAAxx prior to January 31, 2014, and ESWAxx prior to January 31, 2014. An unauthenticated attacker may be able to access configuration files with a specially crafted URL (Path Traversal).Show less
1Eaton
1Elcsoft
May 6, 2026
Jul 3, 2016
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
Stack-based buffer overflow in ELCSimulator in Eaton ELCSoft 2.4.01 and earlier allows remote attackers to execute arbitrary code via a long packet.
1Eaton
1Elcsoft
May 6, 2026
Jul 3, 2016
N/A· v4
6.0 MEDIUM· v3
6.0 MEDIUM· v2
Heap-based buffer overflow in elcsoft.exe in Eaton ELCSoft 2.4.01 and earlier allows remote authenticated users to execute arbitrary code via a crafted file.
1Eaton
1Proview
May 6, 2026
Dec 23, 2015
N/A· v4
5.3 MEDIUM· v3
4.3 MEDIUM· v2
Eaton Cooper Power Systems ProView 4.x and 5.x before 5.1 on Form 6 controls and Idea and IdeaPLUS relays does not properly initialize padding fields in Ethernet packets, which allows remote attackers to obtain sensitive...Show more
Eaton Cooper Power Systems ProView 4.x and 5.x before 5.1 on Form 6 controls and Idea and IdeaPLUS relays does not properly initialize padding fields in Ethernet packets, which allows remote attackers to obtain sensitive information by reading packet data.Show less
1Eaton
1Proview
May 6, 2026
Jul 20, 2015
N/A· v4
N/A· v3
9.3 HIGH· v2
Eaton Cooper Power Systems ProView 4.0 and 5.0 before 5.0 11 on Form 6 controls and Idea and IdeaPLUS relays generates TCP initial sequence number (ISN) values linearly, which makes it easier for remote attackers to spoo...Show more
Eaton Cooper Power Systems ProView 4.0 and 5.0 before 5.0 11 on Form 6 controls and Idea and IdeaPLUS relays generates TCP initial sequence number (ISN) values linearly, which makes it easier for remote attackers to spoof TCP sessions by predicting an ISN value.Show less
1Eaton
1Network Shutdown Module
Apr 23, 2026
May 28, 2009
N/A· v4
N/A· v3
10.0 HIGH· v2
Eaton MGEOPS Network Shutdown Module before 3.10 Build 13 allows remote attackers to execute arbitrary code by adding a custom action to the MGE frontend via pane_actionbutton.php, and then executing this action via exec...Show more
Eaton MGEOPS Network Shutdown Module before 3.10 Build 13 allows remote attackers to execute arbitrary code by adding a custom action to the MGE frontend via pane_actionbutton.php, and then executing this action via exec_action.php.Show less