CVE-2026-22613
Severity CVSS v4.0:
Pending analysis
Type:
CWE-295
Improper Certificate Validation
Publication date:
09/02/2026
Last modified:
09/02/2026
Description
The server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potentially allowing an attacker to perform a Man-in-the-middle attack. This security issue has been fixed in the latest firmware version of Eaton <br />
<br />
Network M3<br />
<br />
which is available on the Eaton download center.
Impact
Base Score 3.x
5.70
Severity 3.x
MEDIUM



