CVE-2026-22616
Authentication Bypass via Insufficient Rate Limiting in Eaton IPP
Publication date: 2026-04-16
Last updated on: 2026-04-22
Assigner: Eaton
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| eaton | intelligent_power_protector | to 2.00 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-307 | The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame. |
Attack-Flow Graph
AI Powered Q&A
How can this vulnerability impact me? :
This vulnerability can allow attackers to perform brute force attacks on the login page, potentially leading to unauthorized access if valid credentials are discovered. It may result in compromised confidentiality and integrity of the system.
Can you explain this vulnerability to me?
The vulnerability in Eaton Intelligent Power Protector (IPP) software allows an attacker to make repeated authentication attempts against the web interface login page because the software lacks sufficient rate-limiting controls.
What immediate steps should I take to mitigate this vulnerability?
To mitigate this vulnerability, update Eaton Intelligent Power Protector (IPP) software to the latest version available on the Eaton download centre where the issue has been fixed.
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
The vulnerability in Eaton Intelligent Power Protector (IPP) software allows repeated authentication attempts due to insufficient rate-limiting controls. This could potentially increase the risk of unauthorized access to the system.
Such unauthorized access risks may impact compliance with standards and regulations like GDPR and HIPAA, which require adequate security measures to protect sensitive data and prevent unauthorized access.
However, the provided information does not explicitly state the direct impact on compliance with these regulations.