CVE-2018-9280

MEDIUM

Eaton 9px Ups Firmware - Insufficiently Protected Credentials

Title source: rule

Description

An issue was discovered on Eaton UPS 9PX 8000 SP devices. The appliance discloses the SNMP version 3 user's password. The web page displayed by the appliance contains the password in cleartext. Passwords of the read and write users could be retrieved by browsing the source code of the webpage.

Scores

CVSS v3 4.9
EPSS 0.0031
EPSS Percentile 53.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-522
Status published

Affected Products (1)

eaton/9px_ups_firmware

Timeline

Published Oct 24, 2018
Tracked Since Feb 18, 2026