CVE-2018-9279
Summary
| CVE | CVE-2018-9279 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-10-24 21:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | An issue was discovered on Eaton UPS 9PX 8000 SP devices. The appliance discloses the user's password. The web page displayed by the appliance contains the password in cleartext. Passwords could be retrieved by browsing the source code of the webpage. |
Risk And Classification
Problem Types: CWE-522
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Eaton | 9px Ups | - | All | All | All |
| Hardware | Eaton | 9px Ups | - | All | All | All |
| Operating System | Eaton | 9px Ups Firmware | - | All | All | All |
| Operating System | Eaton | 9px Ups Firmware | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Eaton UPS 9PX 8000 SP - Multiple Vulnerabilities - Bishop Fox | MISC | www.bishopfox.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.