QID 591368

Date Published: 2023-04-03

QID 591368: Eaton Power Xpert Gateway models buffer overflow Vulnerability (ETN-SB-2015-1002)

AFFECTED PRODUCTS
PXG 200E
PXG 400E
PXG 600E
PXG 800E
PXM 2000
PXMP
PXM 4000/6000/8000

QID Detection Logic:
This QID checks for the Vulnerable version of Eaton Power Xpert Gateway models using passive scanning.

GHOST is a 'buffer overflow' bug affecting function calls in the glibc library that could potentially allow someone to execute remote code. The vulnerability is reported against glibc libraries versions 2.2 to 2.17.

  • CVSS V3 rated as Low - 0 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ETN-SB-2015-1002 for affected packages and patching details.

    CVEs related to QID 591368

    Software Advisories
    Advisory ID Software Component Link
    ETN-SB-2015-1002 URL Logo www.eaton.com/content/dam/eaton/company/news-insights/cybersecurity/security-bulletins/glibc-(GHOST)-vulnerability.pdf