HIGH🇬🇧 English

CVE-2014-9196

CVSS 7.6v2.0pub. 2015-07-20upd. 2026-05-06

Eaton Cooper Power Systems ProView 4.0 and 5.0 before 5.0 11 on Form 6 controls and Idea and IdeaPLUS relays generates TCP initial sequence number (ISN) values linearly, which makes it easier for remote attackers to spoof TCP sessions by predicting an ISN value.

oryginał EN
CVSS Vector
AV:N/AC:H/Au:N/C:C/I:C/A:C
  • Eaton Proview

    APP
    Eaton
    4.05.05.0.15.0.105.0.25.0.35.0.45.0.55.0.65.0.75.0.85.0.9
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2015-6471MEDIUM5.3ten sam produkt

Eaton Cooper Power Systems ProView 4.x and 5.x before 5.1 on Form 6 controls and Idea and IdeaPLUS relays does...

CVE-2021-23281CRITICAL10.0PL ✓ten sam vendor

Eaton IPM – nieuwierzytelniony RCE przez fałszywy serwer SNMP

CVE-2018-16158CRITICAL9.8PL ✓ten sam vendor

Eaton Power Xpert Meter — zakodowany klucz SSH umożliwia logowanie jako root

CVE-2018-8847CRITICAL9.8PL ✓ten sam vendor

Stack-based buffer overflow w Eaton 9000X Drive umożliwiający RCE

CVE-2018-12031CRITICAL9.8PL ✓ten sam vendor

Path Traversal (LFI) w Eaton Intelligent Power Manager v1.6