Eaton
cpe:2.3:h:eaton:9000x:*:*:*:*:*:*:*, +1 more
A vulnerability exists in the server identity check mechanism for firmware upgrades conducted through the command shell. The implementation is insecure, potentially enabling an attacker to execute a man-in-the-middle attack. This issue has been addressed in the latest version available on the Eaton Download Center.
Exploitation of this vulnerability could lead to unauthorized interception and manipulation of firmware upgrade processes, allowing an attacker to introduce malicious firmware or disrupt the upgrade process.
Users are advised to update to the latest version available on the Eaton Download Center.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.