VendorsEatonintelligent_power_protectorall versions
Vulnerabilities

Eaton Intelligent Power Protector

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2021-23279
Arbitrary File delete
Published 2021-04-13 · Modified
10.0EPSS 0.271
CVE-2021-23277
Improper Neutralization of Directives in Dynamically Evaluated Code
Published 2021-04-13 · Modified
10.0EPSS 0.010
CVE-2021-23280
Arbitrary File upload
Published 2021-04-13 · Modified
9.9EPSS 0.009
CVE-2026-22619
Eaton Intelligent Power Protector (IPP) is affected by insecure library loading in its executable, which could lead to arbitrary code execution by an attacker with access to the software package. This security issue has been fixed in the latest version of Eaton IPP software which is available on the Eaton download center.
Published 2026-04-16 · Analyzed
9.9EPSS 0.003
CVE-2021-23278
Arbitrary File delete
Published 2021-04-13 · Modified
9.6EPSS 0.010
CVE-2021-23276
Improper Neutralization of Special Elements used in an SQL Command
Published 2021-04-13 · Modified
8.8EPSS 0.008
CVE-2026-22616
Eaton Intelligent Power Protector (IPP) software allows repeated authentication attempts against the web interface login page due to insufficient rate‑limiting controls. This security issue has been fixed in the latest version of Eaton IPP which is available on the Eaton download centre.
Published 2026-04-16 · Analyzed
7.5EPSS 0.003
CVE-2026-22617
Eaton Intelligent Power Protector (IPP) uses an insecure cookie configuration, which could allow a network‑based attacker to intercept the cookie and exploit it through a man‑in‑the‑middle attack. This security issue has been fixed in the latest version of Eaton IPP software which is available on the Eaton download centre.
Published 2026-04-16 · Analyzed
7.4EPSS 0.002
CVE-2026-22615
Due to improper input validation in one of the Eaton Intelligent Power Protector (IPP) XML, it is possible for an attacker with admin privileges and access to the local system to inject malicious code resulting in arbitrary command execution. This security issue has been fixed in the latest version of Eaton IPP software which is available on the Eaton download centre.
Published 2026-04-16 · Analyzed
7.2EPSS 0.003
CVE-2026-22618
A security misconfiguration was identified in Eaton Intelligent Power Protector (IPP), where an HTTP response header was set with an insecure attribute, potentially exposing users to web‑based attacks. This security issue has been fixed in the latest version of Eaton IPP software which is available on the Eaton download centre.
Published 2026-04-16 · Analyzed
7.1EPSS 0.002
CVE-2021-23288
Security issues in Intelligent Power Protector
Published 2022-04-01 · Modified
5.6EPSS 0.003
CVE-2021-23283
Security issues in Eaton Intelligent Power Protector (IPP)
Published 2022-04-19 · Modified
5.4EPSS 0.005