CVE-2016-9368: Eaton Xcomfort Ethernet Communication Interface
High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.
An issue was discovered in Eaton xComfort Ethernet Communication Interface (ECI) Versions 1.07 and prior. By accessing a specific uniform resource locator (URL) on the webserver, a malicious user may be able to access files without authenticating.
Affected products
- Eaton Xcomfort Ethernet Communication Interface: up to and including 1.07
Published 2017-03-14. Last modified 2026-06-17.