CVE Vulnerabilities

CVE-2018-9279

Insufficiently Protected Credentials

Published: Oct 24, 2018 | Modified: Oct 03, 2019
CVSS 3.x
4.9
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered on Eaton UPS 9PX 8000 SP devices. The appliance discloses the users password. The web page displayed by the appliance contains the password in cleartext. Passwords could be retrieved by browsing the source code of the webpage.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

Name Vendor Start Version End Version
9px_ups_firmware Eaton - (including) - (including)

Potential Mitigations

References