Junglewise Threat Intelligence

CVE-2026-22614: Eaton EasySoft insecure encryption in project files

CVE-2026-22614 · Severity: medium · CVSS 6.1 · Published 2026-03-10

Executive brief

Eaton EasySoft is a software tool used to program and configure control relays and automation devices. A security flaw in how the software protects its project files allows an attacker with local access to the computer to bypass encryption. This could lead to the theft of sensitive configuration data or the unauthorized modification of automation projects, potentially impacting industrial operations.

Technical details

Eaton EasySoft project files utilize an insecure encryption mechanism (CWE-257) that is susceptible to brute-force attacks. An attacker with local access to the host machine and the project file can exploit this weakness to decrypt sensitive information or tamper with the file's contents. The vulnerability requires local access and low privileges to execute. Eaton has addressed this issue in EasySoft version 8.41 by improving the protection of project files.

Affected products

  • Eaton EasySoft versions prior to 8.41

Timeline

  • 2026-03-10: advisory: Initial disclosure by Eaton and NVD publication
  • 2026-05-21: other: NVD analysis and CPE information updated

References