nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-22614 CVE-2026-22614
MEDIUM
Eaton EasySoft Insecure Encryption Leading to Information Disclosure and File Tampering
Record summary
CVE-2026-22614 has a selected CVSS score of 6.1 (medium).
Description
The encryption mechanism used in Eaton's EasySoft project file was insecure and susceptible to brute force attacks, an attacker with access to this file and the local host machine could potentially read the sensitive information stored and tamper with the project file. This security issue has been fixed in the latest version of Eaton EasySoft which is available on the Eaton download centre.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 10, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
EasySoftBrowse Eaton / EasySoftDefault status: unaffected | CVE List | Before 8.4 | affected |
References
2eaton.com
https://www.eaton.com/content/dam/eaton/company/news-insights/cybersecurity/security-bulletins/etn-va-2025-1023.pdf