Vulnerabilities in Eaton

56 results
Vexday analysis

Com 53 CVEs catalogadas e nenhuma em exploração ativa confirmada pelo CISA KEV, o perfil de risco da Eaton situa-se abaixo da média geral do catálogo, o que indica menor pressão imediata de remediação em comparação com outros vendors. A falha mais comum é CWE-20 (validação inadequada de entrada), um padrão recorrente em sistemas de automação e gerenciamento de energia que pode favorecer vetores de injeção ou manipulação de dados. A CVE mais relevante no momento, CVE-2021-23279, apresenta score EPSS de 0,2709 — valor que, embora não indique exploração confirmada, merece atenção por estar entre os mais elevados do portfólio. O surgimento de 5 novas CVEs nos últimos 90 dias e a ausência de PoCs públicas sugerem que a superfície de ataque está em expansão moderada, mas sem pressão imediata de exploração massiva.

CVE-2019-5625LOWEaton Halo Home Android App Insecure StorageEPSS 0.4%CVE-2022-33859HIGHUnrestricted file upload in Eaton Foreseer EPMSEPSS 0.4%CVE-2026-22620HIGHImproper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unauthenticated remote aEPSS 0.4%CVE-2020-6652HIGHIncorrect privilege assignment allowing non-admin users to upload config filesEPSS 0.4%CVE-2026-22615MEDIUMDue to improper input validation in one of the Eaton Intelligent Power Protector (IPP) XML, it is possible for an attacker with admin privilEPSS 0.3%CVE-2025-48396HIGHArbitrary code execution is possible due to improper validation of the file upload functionality in Eaton BLSS. This security issue has beenEPSS 0.3%CVE-2026-22619HIGHEaton Intelligent Power Protector (IPP) is affected by insecure library loading in its executable, which could lead to arbitrary code executEPSS 0.3%CVE-2025-59886HIGHImproper input validation at one of the endpoints of Eaton xComfort ECI's web interface, could lead into an attacker with network access tEPSS 0.3%CVE-2026-22616MEDIUMEaton Intelligent Power Protector (IPP) software allows repeated authentication attempts against the web interface login page due to insuffiEPSS 0.3%CVE-2026-22622HIGHImproper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware could allow an authenticatedEPSS 0.3%CVE-2026-22621HIGHImproper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could allow an authenticatedEPSS 0.3%CVE-2024-31414MEDIUMThe Eaton Foreseer software provides users the capability to customize the dashboard in WebView pages. However, the input fields for this feEPSS 0.3%CVE-2021-23288MEDIUMSecurity issues in Intelligent Power ProtectorEPSS 0.3%CVE-2025-48395MEDIUMAn attacker with authenticated and privileged access could modify the contents of a non-sensitive file by traversing the path in the limitedEPSS 0.3%CVE-2025-48394MEDIUMAn attacker with authenticated and privileged access could modify the contents of a non-sensitive file by traversing the path in the limitedEPSS 0.3%CVE-2023-43777MEDIUMInsecure storage of password in easySoftEPSS 0.3%CVE-2024-31416MEDIUMThe Eaton Foreseer software provides multiple customizable input fields for the users to configure parameters in the tool like alarms, reporEPSS 0.3%CVE-2020-6653LOWSensitive date stored in logcat fileEPSS 0.3%CVE-2025-59887HIGHImproper authentication of library files in the Eaton UPS Companion software installer could lead to arbitrary code execution of an attackerEPSS 0.3%CVE-2026-22618MEDIUMA security misconfiguration was identified in Eaton Intelligent Power Protector (IPP), where an HTTP response header was set with an insecurEPSS 0.2%