Vulnerabilities > Eaton > High

DATE CVE VULNERABILITY TITLE RISK
2019-05-22 CVE-2019-5625 Insufficiently Protected Credentials vulnerability in Eaton Halo Home 1.9.0
The Android mobile application Halo Home before 1.11.0 stores OAuth authentication and refresh access tokens in a clear text file.
local
low complexity
eaton CWE-522
7.1
2018-10-24 CVE-2018-9281 Cross-site Scripting vulnerability in Eaton 9PX UPS Firmware
An issue was discovered on Eaton UPS 9PX 8000 SP devices.
network
low complexity
eaton CWE-79
8.8
2017-03-14 CVE-2016-9368 Improper Access Control vulnerability in Eaton Xcomfort Ethernet Communication Interface 1.07
An issue was discovered in Eaton xComfort Ethernet Communication Interface (ECI) Versions 1.07 and prior.
network
low complexity
eaton CWE-284
7.5
2016-07-03 CVE-2016-4512 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Eaton Elcsoft 1.00.08/2.4.01
Stack-based buffer overflow in ELCSimulator in Eaton ELCSoft 2.4.01 and earlier allows remote attackers to execute arbitrary code via a long packet.
network
low complexity
eaton CWE-119
7.3