CVE-2016-9357
Summary
| CVE | CVE-2016-9357 |
|---|---|
| State | PUBLISHED |
| Assigner | icscert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-02-13 21:59:02 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | An issue was discovered in certain legacy Eaton ePDUs -- the affected products are past end-of-life (EoL) and no longer supported: EAMxxx prior to June 30, 2015, EMAxxx prior to January 31, 2014, EAMAxx prior to January 31, 2014, EMAAxx prior to January 31, 2014, and ESWAxx prior to January 31, 2014. An unauthenticated attacker may be able to access configuration files with a specially crafted URL (Path Traversal). |
Risk And Classification
Primary CVSS: v3.0 5.3 MEDIUM from [email protected]
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Problem Types: CWE-22 | Eaton ePDU Path Traversal Vulnerability
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 5.3 | MEDIUM | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
| 2.0 | [email protected] | Primary | 5 | AV:N/AC:L/Au:N/C:P/I:N/A:N |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
LowIntegrity
NoneAvailability
NoneCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Eaton | Eamaxx Series Epdu | - | All | All | All |
| Operating System | Eaton | Eamaxx Series Epdu Firmware | All | All | All | All |
| Hardware | Eaton | Eamxxx Series Epdu | - | All | All | All |
| Operating System | Eaton | Eamxxx Series Epdu Firmware | All | All | All | All |
| Hardware | Eaton | Emaaxx Series Epdu | - | All | All | All |
| Operating System | Eaton | Emaaxx Series Epdu Firmware | All | All | All | All |
| Hardware | Eaton | Emaxxx Series Epdu | - | All | All | All |
| Operating System | Eaton | Emaxxx Series Epdu Firmware | All | All | All | All |
| Hardware | Eaton | Eswaxx Series Epdu | - | All | All | All |
| Operating System | Eaton | Eswaxx Series Epdu Firmware | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Na | Eaton EPDU EoL Devices | affected Eaton ePDU EoL devices | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Eaton ePDU Path Traversal Vulnerability | ICS-CERT | af854a3a-2127-422b-91ae-364da2661108 | ics-cert.us-cert.gov | Third Party Advisory, US Government Resource |
| Multiple Eaton ePDU Products CVE-2016-9357 Directory Traversal Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.