Vulnerabilidades em Eaton

56 resultados
Análise Vexday

Com 53 CVEs catalogadas e nenhuma em exploração ativa confirmada pelo CISA KEV, o perfil de risco da Eaton situa-se abaixo da média geral do catálogo, o que indica menor pressão imediata de remediação em comparação com outros vendors. A falha mais comum é CWE-20 (validação inadequada de entrada), um padrão recorrente em sistemas de automação e gerenciamento de energia que pode favorecer vetores de injeção ou manipulação de dados. A CVE mais relevante no momento, CVE-2021-23279, apresenta score EPSS de 0,2709 — valor que, embora não indique exploração confirmada, merece atenção por estar entre os mais elevados do portfólio. O surgimento de 5 novas CVEs nos últimos 90 dias e a ausência de PoCs públicas sugerem que a superfície de ataque está em expansão moderada, mas sem pressão imediata de exploração massiva.

CVE-2021-23279HIGHArbitrary File deleteEPSS 27.1%CVE-2021-23282MEDIUMStored Cross-site Scripting reported in Intelligent Power Manager v1EPSS 8.4%CVE-2020-6656MEDIUMFile parsing Type Confusion Remote code execution vulerabilityEPSS 2.7%CVE-2020-6655MEDIUMFile parsing Out-Of-Bounds read remote code executionEPSS 2.7%CVE-2021-23281CRITICALRemote Code executionEPSS 2.2%CVE-2020-6651HIGHCommand injection via specially crafted file name during config file uploadEPSS 2.1%CVE-2020-6650HIGHArbitrary code execution through “Update Manager” ClassEPSS 2.1%CVE-2018-7511In Eaton ELCSoft versions 2.04.02 and prior, there are multiple cases where specially crafted files could cause a buffer overflow which, in EPSS 2.1%CVE-2021-23278HIGHArbitrary File deleteEPSS 1.0%CVE-2021-23277HIGHImproper Neutralization of Directives in Dynamically Evaluated CodeEPSS 1.0%CVE-2021-23280HIGHArbitrary File uploadEPSS 0.9%CVE-2021-23276HIGHImproper Neutralization of Special Elements used in an SQL CommandEPSS 0.8%CVE-2023-43775MEDIUMSecurity issue in SMP Gateway automation platformEPSS 0.7%CVE-2026-22621HIGHImproper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could allow an authenticatedEPSS 0.6%CVE-2021-23283MEDIUMSecurity issues in Eaton Intelligent Power Protector (IPP)EPSS 0.5%CVE-2021-23284MEDIUMSecurity issues in Eaton Intelligent Power Manager InfrastructureEPSS 0.5%CVE-2021-23287MEDIUMSecurity issues in Intelligent Power Manager (IPM 1)EPSS 0.5%CVE-2025-22495HIGHAn improper input validation vulnerability was discovered in the NTP server configuration field of the Network-M2 card. This could result inEPSS 0.4%CVE-2020-6654HIGHDLL HijackingEPSS 0.4%CVE-2019-5625LOWEaton Halo Home Android App Insecure StorageEPSS 0.4%