An issue was discovered on Eaton UPS 9PX 8000 SP devices. The administration panel is vulnerable to a CSRF attack on the change-password functionality. This vulnerability could be used to force a logged-in administrator to perform a silent password update. The affected forms are also vulnerable to Reflected Cross-Site Scripting vulnerabilities. This flaw could be triggered by driving an administrator logged into the Eaton application to a specially crafted web page. This attack could be done silently.
References
Link | Resource |
---|---|
https://www.bishopfox.com/news/2018/10/eaton-ups-9px-8000-sp-multiple-vulnerabilities/ | Third Party Advisory |
https://www.bishopfox.com/news/2018/10/eaton-ups-9px-8000-sp-multiple-vulnerabilities/ | Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 04:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.bishopfox.com/news/2018/10/eaton-ups-9px-8000-sp-multiple-vulnerabilities/ - Third Party Advisory |
Information
Published : 2018-10-24 21:29
Updated : 2024-11-21 04:15
NVD link : CVE-2018-9281
Mitre link : CVE-2018-9281
CVE.ORG link : CVE-2018-9281
JSON object : View
Products Affected
eaton
- 9px_ups_firmware
- 9px_ups