Eaton Cooper Power Systems ProView 4.0 and 5.0 before 5.0 11 on Form 6 controls and Idea and IdeaPLUS relays generates TCP initial sequence number (ISN) values linearly, which makes it easier for remote attackers to spoof TCP sessions by predicting an ISN value.
CVSS Vector
AV:N/AC:H/Au:N/C:C/I:C/A:CEaton Proview
APPEaton4.05.05.0.15.0.105.0.25.0.35.0.45.0.55.0.65.0.75.0.85.0.9
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2015-6471MEDIUM5.3same product
Eaton Cooper Power Systems ProView 4.x and 5.x before 5.1 on Form 6 controls and Idea and IdeaPLUS relays does...
CVE-2021-23281CRITICAL10.0PL ✓same vendor
Eaton IPM – nieuwierzytelniony RCE przez fałszywy serwer SNMP
CVE-2018-16158CRITICAL9.8PL ✓same vendor
Eaton Power Xpert Meter — zakodowany klucz SSH umożliwia logowanie jako root
CVE-2018-8847CRITICAL9.8PL ✓same vendor
Stack-based buffer overflow w Eaton 9000X Drive umożliwiający RCE
CVE-2018-12031CRITICAL9.8PL ✓same vendor
Path Traversal (LFI) w Eaton Intelligent Power Manager v1.6