CVE-2018-9280

MEDIUM

Eaton 9PX UPS 8000 SP - Insufficiently Protected SNMPv3 Credentials

Title source: llm
STIX 2.1

Description

An issue was discovered on Eaton UPS 9PX 8000 SP devices. The appliance discloses the SNMP version 3 user's password. The web page displayed by the appliance contains the password in cleartext. Passwords of the read and write users could be retrieved by browsing the source code of the webpage.

References (1)

Core 1

Scores

CVSS v3 4.9
EPSS 0.0104
EPSS Percentile 59.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-522
Status published
Products (1)
eaton/9px_ups_firmware
Published Oct 24, 2018
Tracked Since Feb 18, 2026