First published: Wed Oct 24 2018(Updated: )
An issue was discovered on Eaton UPS 9PX 8000 SP devices. The appliance discloses the SNMP version 3 user's password. The web page displayed by the appliance contains the password in cleartext. Passwords of the read and write users could be retrieved by browsing the source code of the webpage.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Eaton 9px Ups Firmware | ||
Eaton 9px Ups |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2018-9280.
The affected software for this vulnerability is Eaton UPS 9PX 8000 SP devices with the Eaton 9px Ups Firmware.
The severity of CVE-2018-9280 is medium with a CVSS score of 4.9.
An attacker can exploit this vulnerability by browsing the source code of the webpage displayed by the appliance to retrieve the cleartext passwords of the SNMP version 3 user.
It is recommended to contact Eaton for any available fixes or patches for CVE-2018-9280.