Impact
The vulnerability is an improper input validation flaw in the authentication component of Eaton Tripp Lite PADM firmware. This flaw allows an unauthenticated remote attacker to supply crafted input that bypasses login controls and gains privileged user access to the device. The issue is classified as CWE-89.
Affected Systems
Eaton Tripp Lite PADM firmware is affected. No specific firmware build or release numbers are disclosed, so all deployments of the PADM firmware are potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.6 classifies the issue as high severity. The EPSS score is less than 1 %, indicating a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is the network: an unauthenticated remote attacker can trigger the authentication bypass by sending specially crafted input to the device’s login interface. Successful exploitation results in privileged administrative control of the device.
OpenCVE Enrichment