CVE-2018-9281
Last modified
CVE-2018-9281 is a vulnerability of currently unknown severity. An issue was discovered on Eaton UPS 9PX 8000 SP devices. The administration panel is vulnerable to a CSRF attack on the change-password functionality. EPSS estimates a 0.43% chance of exploitation in the next 30 days.
Description
An issue was discovered on Eaton UPS 9PX 8000 SP devices. The administration panel is vulnerable to a CSRF attack on the change-password functionality. This vulnerability could be used to force a logged-in administrator to perform a silent password update. The affected forms are also vulnerable to Reflected Cross-Site Scripting vulnerabilities. This flaw could be triggered by driving an administrator logged into the Eaton application to a specially crafted web page. This attack could be done silently.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Eaton | 9px Ups Firmware | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-9281?
How severe is CVE-2018-9281?
How do I fix CVE-2018-9281?
Are you affected by CVE-2018-9281?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
