← Back to home
ICSA-17-026-01  ·  Published 2017-01-26  ·  View on CISA ICS-CERT ↗

Eaton ePDU Path Traversal Vulnerability

CVSS 5.3 MEDIUM

Risk Summary

Independent researcher Maxim Rupp has identified a path traversal vulnerability in certain legacy Eaton ePDUs. Although the affected products are past end-of-life (EoL) and is no longer supported, Eaton has provided defense-in-depth mitigation instructions to protect devices that are still in use.

CVEs (1)

Remediations

  • Eaton declared these products EoL on January 31, 2014, and June 30, 2015. Eaton recommends that users of the affected legacy products follow the recommendations outlined in the Defense in depth section of Eaton's whitepaper titled Cybersecurity considerations for electrical distribution systems. It is located at:
  • Additional information regarding these and other legacy products can be found on the Eaton web site.

Affected Vendors

Eaton

Affected Products (5)

Eaton · EAMAxx < January 31 2014
Eaton · EMAxxx < January 31 2014
Eaton · ESWAxx < January 31 2014
Eaton · EMAAxx < January 31 2014
Eaton · EAMxxx < June 30 2015

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more