Eaton Cooper Power Systems ProView 4.x and 5.x before 5.1 on Form 6 controls and Idea and IdeaPLUS relays does not properly initialize padding fields in Ethernet packets, which allows remote attackers to obtain sensitive information by reading packet data.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NEaton Proview
APPEaton4.05.05.0.15.0.105.0.25.0.35.0.45.0.55.0.65.0.75.0.85.0.9
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2014-9196HIGH7.6same product
Eaton Cooper Power Systems ProView 4.0 and 5.0 before 5.0 11 on Form 6 controls and Idea and IdeaPLUS relays g...
CVE-2021-23281CRITICAL10.0PL ✓same vendor
Eaton IPM – nieuwierzytelniony RCE przez fałszywy serwer SNMP
CVE-2018-16158CRITICAL9.8PL ✓same vendor
Eaton Power Xpert Meter — zakodowany klucz SSH umożliwia logowanie jako root
CVE-2018-8847CRITICAL9.8PL ✓same vendor
Stack-based buffer overflow w Eaton 9000X Drive umożliwiający RCE
CVE-2018-12031CRITICAL9.8PL ✓same vendor
Path Traversal (LFI) w Eaton Intelligent Power Manager v1.6