PT-2026-7071 · Eaton · Eaton Network M3
CVE-2026-22613
·
Publicado
2026-02-09
·
Atualizado
2026-02-09
CVSS v3.1
5.7
Média
| Vetor | AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Eaton Network M3 (affected versions not specified)
Description
The server identity check during firmware upgrades via the command shell is implemented insecurely, potentially enabling a Man-in-the-middle attack. This could allow an attacker to intercept and modify the firmware update process.
Recommendations
Update to the latest firmware version of Eaton Network M3, available on the Eaton download center.
Correção
Improper Certificate Validation
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Eaton Network M3