Vulnerabilities > Eaton > Low

DATE CVE VULNERABILITY TITLE RISK
2022-04-19 CVE-2021-23283 Cross-site Scripting vulnerability in Eaton Intelligent Power Protector
Eaton Intelligent Power Protector (IPP) prior to version 1.69 is vulnerable to stored Cross Site Scripting.
network
eaton CWE-79
3.5
2022-04-01 CVE-2021-23288 Cross-site Scripting vulnerability in Eaton Intelligent Power Protector
The vulnerability exists due to insufficient validation of input from certain resources by the IPP software.
2.3
2022-04-01 CVE-2021-23287 Cross-site Scripting vulnerability in Eaton Intelligent Power Manager 1.6/1.67/1.69
The vulnerability exists due to insufficient validation of input of certain resources within the IPM software.
network
eaton CWE-79
3.5
2020-08-12 CVE-2020-6653 Information Exposure vulnerability in Eaton Secureconnect 1.7.3
Eaton's Secure connect mobile app v1.7.3 & prior stores the user login credentials in logcat file when user create or register the account on the Mobile app.
local
low complexity
eaton CWE-200
2.1
2020-01-22 CVE-2020-7915 Cross-site Scripting vulnerability in Eaton 5P 850 Firmware
An issue was discovered on Eaton 5P 850 devices.
network
eaton CWE-79
3.5
2019-05-22 CVE-2019-5625 Insufficiently Protected Credentials vulnerability in Eaton Halo Home 1.9.0
The Android mobile application Halo Home before 1.11.0 stores OAuth authentication and refresh access tokens in a clear text file.
local
low complexity
eaton CWE-522
3.6