Vulnerabilidades em Eaton

56 resultados
Análise Vexday

Com 53 CVEs catalogadas e nenhuma em exploração ativa confirmada pelo CISA KEV, o perfil de risco da Eaton situa-se abaixo da média geral do catálogo, o que indica menor pressão imediata de remediação em comparação com outros vendors. A falha mais comum é CWE-20 (validação inadequada de entrada), um padrão recorrente em sistemas de automação e gerenciamento de energia que pode favorecer vetores de injeção ou manipulação de dados. A CVE mais relevante no momento, CVE-2021-23279, apresenta score EPSS de 0,2709 — valor que, embora não indique exploração confirmada, merece atenção por estar entre os mais elevados do portfólio. O surgimento de 5 novas CVEs nos últimos 90 dias e a ausência de PoCs públicas sugerem que a superfície de ataque está em expansão moderada, mas sem pressão imediata de exploração massiva.

CVE-2025-48397HIGHThe privileged user could log in without sufficient credentials after enabling an application protocol. This security issue has been fixed iEPSS 0.2%CVE-2025-48393MEDIUMThe server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potentially allowing an attacEPSS 0.2%CVE-2025-22491MEDIUMImproper Input Validation in Foreseer Reporting Software (FRS)EPSS 0.2%CVE-2025-59888MEDIUMImproper quotation in search paths in the Eaton UPS Companion software installer could lead to arbitrary code execution of an attacker with EPSS 0.2%CVE-2022-33862MEDIUMImproper access control mechanism in IPPEPSS 0.2%CVE-2025-59889HIGHImproper authentication of library files in the Eaton IPP software installer could lead to arbitrary code execution of an attacker with the EPSS 0.2%CVE-2026-22617MEDIUMEaton Intelligent Power Protector (IPP) uses an insecure cookie configuration, which could allow a network‑based attacker to intercept the cEPSS 0.2%CVE-2025-22492MEDIUMInsecure storage of connection strings in FRSEPSS 0.2%CVE-2026-22613MEDIUMThe server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potentially allowing an attacEPSS 0.2%CVE-2025-59890HIGHImproper input sanitization in the file archives upload functionality of Eaton Galileo software allows traversing paths which could lead intEPSS 0.1%CVE-2025-67450HIGHDue to insecure library loading in the Eaton UPS Companion software executable, an attacker with access to the software package could perfEPSS 0.1%CVE-2023-43776MEDIUMWeak encoding vulnerability in easyE4EPSS 0.1%CVE-2024-31415MEDIUMThe Eaton Foreseer software provides the feasibility for the user to configure external servers for multiple purposes such as network manageEPSS 0.1%CVE-2022-33861MEDIUMInsufficient verification of authenticity in IPPEPSS 0.1%CVE-2025-22493MEDIUMImproper cookie attributes in Foreseer Reporting Software (FRS)EPSS 0.1%CVE-2026-22614MEDIUMThe encryption mechanism used in Eaton's EasySoft project file was insecure and susceptible to brute force attacks, an attacker with access EPSS 0.1%