Back to CVE List

CVE-2026-22613

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
5.7 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:L

Vulnerability Description

The server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potentially allowing an attacker to perform a Man-in-the-middle attack. This security issue has been fixed in the latest firmware version of Eaton

Network M3

which is available on the Eaton download center.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-295
Source
NVD
Vendor
Eaton
Product
Network M3

External References

Discussion (0)

Add Comment

No comments yet. Be the first!