CVE-2023-43776: Eaton Easy-Box-e4-AC1 Firmware
Medium severity, CVSS 6.6. EPSS: 0.1% chance of exploitation in the next 30 days.
Eaton easyE4 PLC offers a device password protection functionality to facilitate a secure connection and prevent unauthorized access. It was observed that the device password was stored with a weak encoding algorithm in the easyE4 program file when exported to SD card (*.PRG file ending).
Affected products
- Eaton Easy-Box-e4-AC1 Firmware: before 2.02 (fixed in 2.02)
- Eaton Easy-Box-e4-DC1 Firmware: before 2.02 (fixed in 2.02)
- Eaton Easy-Box-e4-UC1 Firmware: before 2.02 (fixed in 2.02)
- Eaton Easy-e4-Ac-12rc1p Firmware: before 2.02 (fixed in 2.02)
- Eaton Easy-e4-Ac-12rcx1p Firmware: before 2.02 (fixed in 2.02)
- Eaton Easy-e4-Ac-16re1p Firmware: before 2.02 (fixed in 2.02)
- Eaton Easy-e4-DC-12tc1p Firmware: before 2.02 (fixed in 2.02)
- Eaton Easy-e4-DC-12tcx1p Firmware: before 2.02 (fixed in 2.02)
- Eaton Easy-e4-DC-16te1p Firmware: before 2.02 (fixed in 2.02)
- Eaton Easy-e4-DC-4pe1p Firmware: before 2.02 (fixed in 2.02)
- Eaton Easy-e4-DC-6ae1p Firmware: before 2.02 (fixed in 2.02)
- Eaton Easy-e4-DC-8te1p Firmware: before 2.02 (fixed in 2.02)
- Eaton Easy-e4-Uc-12rc1p Firmware: before 2.02 (fixed in 2.02)
- Eaton Easy-e4-Uc-12rcx1p Firmware: before 2.02 (fixed in 2.02)
- Eaton Easy-e4-Uc-16re1 Firmware: before 2.02 (fixed in 2.02)
- Eaton Easy-e4-Uc-16re1p Firmware: before 2.02 (fixed in 2.02)
- Eaton Easy-e4-Uc-8re1p Firmware: before 2.02 (fixed in 2.02)
- Eaton Easy e4-Ac-8re1p Firmware: before 2.02 (fixed in 2.02)
- Eaton Xv-102-a035tqrb-1e4 Firmware: before 2.02 (fixed in 2.02)
- Eaton Xv-102-a3-57tvrb-1e4 Firmware: before 2.02 (fixed in 2.02)
- Eaton XV100-Box-e4-DC1 Firmware: before 2.02 (fixed in 2.02)
- Eaton XV100-Box-e4-UC1 Firmware: before 2.02 (fixed in 2.02)
Published 2023-10-17. Last modified 2026-06-17.