First published: Wed Oct 24 2018(Updated: )
An issue was discovered on Eaton UPS 9PX 8000 SP devices. The appliance discloses the user's password. The web page displayed by the appliance contains the password in cleartext. Passwords could be retrieved by browsing the source code of the webpage.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Eaton 9px Ups Firmware | ||
Eaton 9px Ups |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-9279 is a vulnerability that affects Eaton UPS 9PX 8000 SP devices, where the appliance discloses the user's password in cleartext on the web page source code.
The severity of CVE-2018-9279 is medium, with a severity value of 4.9.
CVE-2018-9279 allows attackers to retrieve passwords by browsing the source code of the webpage displayed by the appliance.
The affected software of CVE-2018-9279 is Eaton 9px Ups Firmware.
To fix CVE-2018-9279, it is recommended to update the Eaton 9px Ups Firmware to a patched version that no longer discloses passwords.