Database/Firmware, BMC & network fabric

Eaton UPS 9PX 8000 SP web interface: The device's own web page contains the user password in cleartext in the page
Impact
The device's own web page contains the user password in cleartext in the page source. Anyone who gets a single authenticated view - or a screenshot, or a saved page in a support ticket - has the credential. The companion issue CVE-2018-9280 does the same for the SNMPv3 read and write user passwords, which is worse, because the SNMP write community is a control channel.
Who can reach it
Anyone who can load the UPS web interface, or who obtains a saved copy of the page.
What to do
Firmware update where available. Rotate the UPS and SNMPv3 credentials, and specifically rotate the SNMP write credential - and then ask whether SNMP write needs to be enabled at all, because on most UPS deployments it does not.
References
Related entries
- NVIDIA DGX BMC (AMI firmware): An administrative BMC user can pull the hash of the BMC/IPMI user passwordCVE-2020-11484 · NVIDIA DGX BMC (AMI firmware)Medium
- AMI MegaRAC SPx 12 / SPx 13 (BMC TLS certificate generation): Malformed input to the BMC's certificate-generationCVE-2021-44769 · AMI MegaRAC SPx 12 / SPx 13 (BMC TLS certificate generation)Medium
- IBM OpenBMC OP910 / OP940 certificate handling (phosphor-certificate-manager lineage): A privileged BMC userCVE-2022-22488 · IBM OpenBMC OP910 / OP940 certificate handling (phosphor-certificate-manager lineage)Medium
- Intel SPS firmware: Uncontrolled resource consumption in SPS firmware lets a privileged user deny serviceCVE-2023-29153 · Intel SPS firmwareMedium
- Dell PowerEdge Server BIOS + iDRAC9 (information disclosure): Information disclosure spanning both the BIOS and iDRAC9CVE-2025-26482 · Dell PowerEdge Server BIOS + iDRAC9 (information disclosure)Medium
- IBM OpenBMC: password supplied with a resource dump request is written to the BMC audit logCVE-2026-8058 · IBM OpenBMC (resource dump request handling, BMC audit log)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.