CVE-2026-22617
Insecure Cookie Configuration in Eaton IPP Enables MITM Attack
Publication date: 2026-04-16
Last updated on: 2026-04-22
Assigner: Eaton
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| eaton | intelligent_power_protector | to 2.00 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-614 | The Secure attribute for sensitive cookies in HTTPS sessions is not set. |
Attack-Flow Graph
AI Powered Q&A
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
The vulnerability involves an insecure cookie configuration in Eaton Intelligent Power Protector (IPP) that could allow a network-based attacker to intercept cookies via a man-in-the-middle attack.
Such interception of sensitive authentication cookies could lead to unauthorized access and compromise of personal or protected data, which may impact compliance with data protection standards and regulations like GDPR and HIPAA that require safeguarding personal and sensitive information.
However, specific impacts on compliance or regulatory requirements are not detailed in the provided information.
Can you explain this vulnerability to me?
The vulnerability in Eaton Intelligent Power Protector (IPP) is due to an insecure cookie configuration. This weakness could allow a network-based attacker to intercept the cookie and exploit it by performing a man-in-the-middle attack.
How can this vulnerability impact me? :
This vulnerability can impact you by allowing an attacker on the network to intercept authentication or session cookies. Through a man-in-the-middle attack, the attacker could potentially hijack your session or gain unauthorized access to the Eaton IPP system, leading to confidentiality and integrity breaches.
What immediate steps should I take to mitigate this vulnerability?
To mitigate this vulnerability, you should update the Eaton Intelligent Power Protector (IPP) software to the latest version available on the Eaton download centre, as this issue has been fixed in that release.