🔐 CVE Alert

CVE-2026-22617

MEDIUM 5.7
CVSS Score
5.7
EPSS Score
0.0%
EPSS Percentile
1th

Eaton Intelligent Power Protector (IPP) uses an insecure cookie configuration, which could allow a network‑based attacker to intercept the cookie and exploit it through a man‑in‑the‑middle attack. This security issue has been fixed in the latest version of Eaton IPP software which is available on the Eaton download centre.

CWE CWE-614
Vendor eaton
Product ipp software
Published Apr 16, 2026
Last Updated Apr 16, 2026
Stay Ahead of the Next One

Get instant alerts for eaton ipp software

Be the first to know when new medium vulnerabilities affecting eaton ipp software are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
High
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

Eaton / IPP Software
0 < 2.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
eaton.com: https://www.eaton.com/content/dam/eaton/company/news-insights/cybersecurity/security-bulletins/etn-va-2025-1025.pdf