Vulnerabilities > Eaton > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-05-07 CVE-2020-6652 Improper Privilege Management vulnerability in Eaton Intelligent Power Manager 1.6/1.67
Incorrect Privilege Assignment vulnerability in Eaton's Intelligent Power Manager (IPM) v1.67 & prior allow non-admin users to upload the system configuration files by sending specially crafted requests.
local
low complexity
eaton CWE-269
4.6
2020-05-07 CVE-2020-6651 Improper Input Validation vulnerability in Eaton Intelligent Power Manager 1.6/1.67
Improper Input Validation in Eaton's Intelligent Power Manager (IPM) v 1.67 & prior on file name during configuration file import functionality allows attackers to perform command injection or code execution via specially crafted file names while uploading the configuration file in the application.
network
eaton CWE-20
6.0
2020-04-15 CVE-2020-10639 Classic Buffer Overflow vulnerability in Eaton Hmisoft VU3 Firmware 3.00.23
Eaton HMiSoft VU3 (HMIVU3 runtime not impacted), Version 3.00.23 and prior, however, the HMIVU runtimes are not impacted by these issues.
network
eaton CWE-120
6.8
2020-04-15 CVE-2020-10637 Out-of-bounds Read vulnerability in Eaton Hmisoft VU3 Firmware 3.00.23
Eaton HMiSoft VU3 (HMIVU3 runtime not impacted), Version 3.00.23 and prior, however, the HMIVU runtimes are not impacted by these issues.
network
eaton CWE-125
4.3
2020-03-23 CVE-2020-6650 Code Injection vulnerability in Eaton UPS Companion
UPS companion software v1.05 & Prior is affected by ‘Eval Injection’ vulnerability.
low complexity
eaton CWE-94
5.8
2018-10-24 CVE-2018-9281 Cross-Site Request Forgery (CSRF) vulnerability in Eaton 9PX UPS Firmware
An issue was discovered on Eaton UPS 9PX 8000 SP devices.
network
eaton CWE-352
6.8
2018-10-24 CVE-2018-9280 Insufficiently Protected Credentials vulnerability in Eaton 9PX UPS Firmware
An issue was discovered on Eaton UPS 9PX 8000 SP devices.
network
low complexity
eaton CWE-522
4.0
2018-10-24 CVE-2018-9279 Insufficiently Protected Credentials vulnerability in Eaton 9PX UPS Firmware
An issue was discovered on Eaton UPS 9PX 8000 SP devices.
network
low complexity
eaton CWE-522
4.0
2018-03-20 CVE-2018-7511 Improper Input Validation vulnerability in Eaton Elcsoft 1.00.08/2.4.01
In Eaton ELCSoft versions 2.04.02 and prior, there are multiple cases where specially crafted files could cause a buffer overflow which, in turn, may allow remote execution of arbitrary code.
network
eaton CWE-20
6.8
2017-03-14 CVE-2016-9368 Improper Access Control vulnerability in Eaton Xcomfort Ethernet Communication Interface 1.07
An issue was discovered in Eaton xComfort Ethernet Communication Interface (ECI) Versions 1.07 and prior.
network
low complexity
eaton CWE-284
5.0