Show filters
49 Total Results
Displaying 41-49 of 49
Sort by:
Attacker Value
Unknown

CVE-2016-9368

Disclosure Date: March 14, 2017 (last updated November 26, 2024)
An issue was discovered in Eaton xComfort Ethernet Communication Interface (ECI) Versions 1.07 and prior. By accessing a specific uniform resource locator (URL) on the webserver, a malicious user may be able to access files without authenticating.
0
Attacker Value
Unknown

CVE-2016-9357

Disclosure Date: February 13, 2017 (last updated November 26, 2024)
An issue was discovered in certain legacy Eaton ePDUs -- the affected products are past end-of-life (EoL) and no longer supported: EAMxxx prior to June 30, 2015, EMAxxx prior to January 31, 2014, EAMAxx prior to January 31, 2014, EMAAxx prior to January 31, 2014, and ESWAxx prior to January 31, 2014. An unauthenticated attacker may be able to access configuration files with a specially crafted URL (Path Traversal).
0
Attacker Value
Unknown

CVE-2016-4512

Disclosure Date: July 03, 2016 (last updated November 25, 2024)
Stack-based buffer overflow in ELCSimulator in Eaton ELCSoft 2.4.01 and earlier allows remote attackers to execute arbitrary code via a long packet.
0
Attacker Value
Unknown

CVE-2016-4509

Disclosure Date: July 03, 2016 (last updated November 25, 2024)
Heap-based buffer overflow in elcsoft.exe in Eaton ELCSoft 2.4.01 and earlier allows remote authenticated users to execute arbitrary code via a crafted file.
0
Attacker Value
Unknown

CVE-2016-0871

Disclosure Date: April 06, 2016 (last updated November 25, 2024)
Eaton Lighting EG2 Web Control 4.04P and earlier allows remote attackers to read the configuration file, and consequently discover credentials, via a direct request.
0
Attacker Value
Unknown

CVE-2016-2272

Disclosure Date: April 06, 2016 (last updated November 25, 2024)
Eaton Lighting EG2 Web Control 4.04P and earlier allows remote attackers to have an unspecified impact via a modified cookie.
0
Attacker Value
Unknown

CVE-2015-6471

Disclosure Date: December 23, 2015 (last updated November 25, 2024)
Eaton Cooper Power Systems ProView 4.x and 5.x before 5.1 on Form 6 controls and Idea and IdeaPLUS relays does not properly initialize padding fields in Ethernet packets, which allows remote attackers to obtain sensitive information by reading packet data.
0
Attacker Value
Unknown

CVE-2014-9196

Disclosure Date: July 20, 2015 (last updated October 05, 2023)
Eaton Cooper Power Systems ProView 4.0 and 5.0 before 5.0 11 on Form 6 controls and Idea and IdeaPLUS relays generates TCP initial sequence number (ISN) values linearly, which makes it easier for remote attackers to spoof TCP sessions by predicting an ISN value.
0
Attacker Value
Unknown

CVE-2008-6816

Disclosure Date: May 28, 2009 (last updated October 04, 2023)
Eaton MGEOPS Network Shutdown Module before 3.10 Build 13 allows remote attackers to execute arbitrary code by adding a custom action to the MGE frontend via pane_actionbutton.php, and then executing this action via exec_action.php.
0