ICSA-17-026-01
·
Published 2017-01-26
·
View on CISA ICS-CERT ↗
Eaton ePDU Path Traversal Vulnerability
CVSS 5.3
MEDIUM
Risk Summary
Independent researcher Maxim Rupp has identified a path traversal vulnerability in certain legacy Eaton ePDUs. Although the affected products are past end-of-life (EoL) and is no longer supported, Eaton has provided defense-in-depth mitigation instructions to protect devices that are still in use.
CVEs (1)
Remediations
- Eaton declared these products EoL on January 31, 2014, and June 30, 2015. Eaton recommends that users of the affected legacy products follow the recommendations outlined in the Defense in depth section of Eaton's whitepaper titled Cybersecurity considerations for electrical distribution systems. It is located at:
- Additional information regarding these and other legacy products can be found on the Eaton web site.
Affected Vendors
Eaton
Affected Products (5)
Eaton
·
EAMAxx
< January 31 2014
Eaton
·
EMAxxx
< January 31 2014
Eaton
·
ESWAxx
< January 31 2014
Eaton
·
EMAAxx
< January 31 2014
Eaton
·
EAMxxx
< June 30 2015
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more