CVE-2018-9279
MEDIUMEaton 9PX UPS 8000 SP - Insufficiently Protected Credentials via Webpage Source Code
Title source: llmDescription
An issue was discovered on Eaton UPS 9PX 8000 SP devices. The appliance discloses the user's password. The web page displayed by the appliance contains the password in cleartext. Passwords could be retrieved by browsing the source code of the webpage.
References (1)
Core 1
Core References
Third Party Advisory x_refsource_misc
https://www.bishopfox.com/news/2018/10/eaton-ups-9px-8000-sp-multiple-vulnerabilities/
Scores
CVSS v3
4.9
EPSS
0.0104
EPSS Percentile
59.6%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-522
Status
published
Products (1)
eaton/9px_ups_firmware
Published
Oct 24, 2018
Tracked Since
Feb 18, 2026