CVE-2018-9280
MEDIUMEaton 9px Ups Firmware - Insufficiently Protected Credentials
Title source: ruleDescription
An issue was discovered on Eaton UPS 9PX 8000 SP devices. The appliance discloses the SNMP version 3 user's password. The web page displayed by the appliance contains the password in cleartext. Passwords of the read and write users could be retrieved by browsing the source code of the webpage.
Scores
CVSS v3
4.9
EPSS
0.0031
EPSS Percentile
53.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-522
Status
published
Affected Products (1)
eaton/9px_ups_firmware
Timeline
Published
Oct 24, 2018
Tracked Since
Feb 18, 2026