Vulnerabilities (CVE)

Filtered by vendor Eaton Subscribe
Filtered by product 9px Ups
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-9281 1 Eaton 2 9px Ups, 9px Ups Firmware 2020-08-24 6.8 MEDIUM 8.8 HIGH
An issue was discovered on Eaton UPS 9PX 8000 SP devices. The administration panel is vulnerable to a CSRF attack on the change-password functionality. This vulnerability could be used to force a logged-in administrator to perform a silent password update. The affected forms are also vulnerable to Reflected Cross-Site Scripting vulnerabilities. This flaw could be triggered by driving an administrator logged into the Eaton application to a specially crafted web page. This attack could be done silently.