Vulnerability index

Browse CVEs

47 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Intelligent Power Manager HIGH 7.3
CVE-2020-6651

Improper Input Validation in Eaton's Intelligent Power Manager (IPM) v 1.67 & prior on file name during configuration file import functionality allow…

Fix: after 1.67
Fix from $1,950 2020-05-07
Hmisoft Vu3 Firmware HIGH 7.8
CVE-2020-10639

Eaton HMiSoft VU3 (HMIVU3 runtime not impacted), Version 3.00.23 and prior, however, the HMIVU runtimes are not impacted by these issues. A specially…

Fix: after 3.00.23
Fix from $1,950 2020-04-15
Hmisoft Vu3 Firmware MEDIUM 5.5
CVE-2020-10637

Eaton HMiSoft VU3 (HMIVU3 runtime not impacted), Version 3.00.23 and prior, however, the HMIVU runtimes are not impacted by these issues. A specially…

Fix: after 3.00.23
Fix from $1,600 2020-04-15
Ups Companion HIGH 8.8
CVE-2020-6650

UPS companion software v1.05 & Prior is affected by ‘Eval Injection’ vulnerability. The software does not neutralize or incorrectly neutralizes code …

Fix: after 1.05
Fix from $1,950 2020-03-23
Halo Home HIGH 7.1
CVE-2019-5625

The Android mobile application Halo Home before 1.11.0 stores OAuth authentication and refresh access tokens in a clear text file. This file persists…

No fix yet
Fix from $1,950 2019-05-22
9px Ups Firmware HIGH 8.8
CVE-2018-9281

An issue was discovered on Eaton UPS 9PX 8000 SP devices. The administration panel is vulnerable to a CSRF attack on the change-password functionalit…

Mitigation only
Fix from $1,950 2018-10-24
Power Xpert Meter 4000 Firmware CRITICAL 9.8
CVE-2018-16158EPSS 35%

Eaton Power Xpert Meter 4000, 6000, and 8000 devices before 13.4.0.10 have a single SSH private key across different customers' installations and do …

Fix: 13.4.0.10+
Fix from $2,300 2018-08-30
9000x Firmware CRITICAL 9.8
CVE-2018-8847EPSS 7%

Eaton 9000X DriveA versions 2.0.29 and prior has a stack-based buffer overflow vulnerability, which may allow remote code execution.

Fix: after 2.0.29
Fix from $2,300 2018-07-13
Intelligent Power Manager CRITICAL 9.8
CVE-2018-12031EPSS 17%

Local file inclusion in Eaton Intelligent Power Manager v1.6 allows an attacker to include a file via server/node_upgrade_srv.js directory traversal …

No fix yet
Fix from $2,300 2018-06-07
Elcsoft MEDIUM 5.3
CVE-2018-7511

In Eaton ELCSoft versions 2.04.02 and prior, there are multiple cases where specially crafted files could cause a buffer overflow which, in turn, may…

Fix: 2.04.02+
Fix from $1,600 2018-03-20
Xcomfort Ethernet Communication Interface HIGH 7.5
CVE-2016-9368

An issue was discovered in Eaton xComfort Ethernet Communication Interface (ECI) Versions 1.07 and prior. By accessing a specific uniform resource lo…

Fix: after 1.07
Fix from $1,950 2017-03-14
Eamxxx Series Epdu Firmware MEDIUM 5.3
CVE-2016-9357

An issue was discovered in certain legacy Eaton ePDUs -- the affected products are past end-of-life (EoL) and no longer supported: EAMxxx prior to Ju…

Fix: after 06-30-2015
Fix from $1,600 2017-02-13
Elcsoft HIGH 7.3
CVE-2016-4512

Stack-based buffer overflow in ELCSimulator in Eaton ELCSoft 2.4.01 and earlier allows remote attackers to execute arbitrary code via a long packet.

Fix: after 2.4.01
Fix from $1,950 2016-07-03
Elcsoft MEDIUM 6.0
CVE-2016-4509

Heap-based buffer overflow in elcsoft.exe in Eaton ELCSoft 2.4.01 and earlier allows remote authenticated users to execute arbitrary code via a craft…

Fix: after 2.4.01
Fix from $1,600 2016-07-03
Proview MEDIUM 5.3
CVE-2015-6471

Eaton Cooper Power Systems ProView 4.x and 5.x before 5.1 on Form 6 controls and Idea and IdeaPLUS relays does not properly initialize padding fields…

Mitigation only
Fix from $1,600 2015-12-23
Proview HIGH 9.3
CVE-2014-9196

Eaton Cooper Power Systems ProView 4.0 and 5.0 before 5.0 11 on Form 6 controls and Idea and IdeaPLUS relays generates TCP initial sequence number (I…

Mitigation only
Fix from $1,950 2015-07-20
Network Shutdown Module HIGH 10.0
CVE-2008-6816

Eaton MGEOPS Network Shutdown Module before 3.10 Build 13 allows remote attackers to execute arbitrary code by adding a custom action to the MGE fron…

Fix: after 3.1_beta
Fix from $1,950 2009-05-28