Descargar documento () de 20
Hacemos que lo importante funcione*

Product vulnerability disclosures and policy

Eaton Product Security and Vulnerability Disclosure Process

At Eaton, cybersecurity is fundamental to delivering safe, reliable, and trusted products and solutions to our customers. We are committed to maintaining the security of our products and working with the security community, customers and others to responsibly address reported vulnerabilities because we believe that collaboration makes everyone safer. 

This page sets out Eaton’s approach to coordinated vulnerability disclosure in accordance with applicable law, including the EU Cyber Resilience Act (CRA). You can also read Eaton’s full Coordinated  Vulnerability Disclosure Policy for complete details on our reporting channels, handling process, safe harbor provisions, remediation approach, and disclosure practices.

What This Policy Covers 

This policy applies to vulnerability reports submitted for the following Eaton products and services:

  • Eaton products, including hardware, software, firmware, and connected assembly solutions that are currently supported; and
  • Eaton Digital Services, including cloud and on-premises service offerings operated by Eaton for customers and business partners.

How to Report a Vulnerability

If you've discovered a potential security issue in an Eaton product or service, we want to hear from you. Vulnerability reports may be submitted by researchers, customers, CERTs, security intelligence agencies, authorized channel partners, or other third-party reporters (“Vulnerability Reporters”) through our designated reporting channels.

To report a vulnerability, please use one of the following channels:

What Happens After You Submit A Report

Once submitted, your report goes directly to our dedicated Product Security Incident Response Team (PSIRT), who will review and investigate the issue. You can expect to hear from us within two business days.

  • If we determine the report is out of scope, does not identify a vulnerability, is a duplicate, or affects an unsupported product,  we will let you know and close the matter.
  • If confirmed, Eaton will determine the most appropriate remediation measures, prioritized based on risk to customers and operations, taking into account the severity, complexity, and potential impact. PSIRT will stay in regular contact with you and communicate an estimated remediation timeline where appropriate.

Eaton publicly discloses vulnerabilities in accordance with applicable law.  High or Critical severity vulnerabilities (CVSS score 7.0 or above) are disclosed through a Vulnerability Advisory (for Eaton products) or Security Bulletin (for third-party components) on our notification page. For lower severity issues, Eaton will handle notifications on a case-by-case basis, typically with direct notice to customers or updates in version release notes. As a CVE Numbering Authority, Eaton will also assign a CVE number to High or Critical vulnerabilities in actively supported products.

Please note that Vulnerability Reporters are asked to respond to any follow-up questions within 30 days, after which the matter may be considered closed.

How We Protect Vulnerability Reporters (Safe Harbor)

Reporting a potential security issue takes trust, and we respect that. Eaton will not pursue legal action against reporters who:

  • Act in good faith and proactively prevent harm to Eaton, its products and services, its customers, business partners and stakeholders.
  • Conduct research and testing within scope of this Policy as defined in “What this Policy Covers” section above, or have received prior written permission from Eaton to conduct testing outside of that scope.
  • Comply with applicable laws, regulations, and this Policy.
  • Avoid data exfiltration, service disruptions, or any activity that impacts the safety or privacy of Eaton, its products, services, customers, business partners, and stakeholders.
  • Provide sufficient information to facilitate the validation of the reported vulnerability.
  • Do not retain, exploit, or disclose any sensitive data or intellectual property inadvertently accessed during research, and notify Eaton immediately if this occurs.
  • Refrain from any form of public disclosure until a disclosure strategy has been coordinated with Eaton, and Eaton has confirmed disclosure is permitted.

Hall of Recognition

Eaton maintains a Hall of Recognition to recognize the contributions of Vulnerability Reporters, below. Eaton will acknowledge Vulnerability Reporters, with their consent, in applicable Vulnerability Advisories or Security Bulletins.

Eaton and the EU Cyber Resilience Act (“CRA”)

The CRA establishes cybersecurity requirements for connected products sold in the European Union. Many Eaton connected products sold in the EU are expected to be in scope. CRA obligations apply from September 2026 (vulnerability handling and incident reporting ) and December 2027 (full CE marking requirements).

Under the CRA, Eaton will:

  • Report actively exploited vulnerabilities to the relevant national CSIRT (national cybersecurity incident response team) and/or ENISA (the EU Agency for Cybersecurity) within 24 hours of becoming aware, with a technical notification within 72 hours and a final report within 14 days.
  • Make Software Bill of Materials (SBOM) documentation available for in-scope products upon request.
  • Publish product security support lifecycle and end-of -life update commitments.

For more information on Eaton’s CRA preparations, visit Eaton’s CRA page. For product-specific information, including SBOM and product security support information, please visit the respective product catalog page.

Eaton security advisories

Public release of information relating to security vulnerabilities is on our Cybersecurity notifications page. This page is the central repository for Eaton product security advisories related to all Eaton electrical products. Customers are encouraged to monitor this portal for latest security advisories.

We intend to issue security advisories for validated vulnerabilities when a practical workaround or fix has been identified. There may be instances when an advisory is issued in the absence of a workaround. Because each security vulnerability is different, we may take alternative actions in connection with issuing security advisories. 

Eaton does not guarantee that security advisories will be issued for any or all security issues that customers may consider significant or that advisories will be issued on any specific timeline.

Note: Eaton reserves the right to modify this policy at any time, in its sole discretion.

Reward and recognition

Eaton maintains a Hall of Recognition to duly recognize the contributions of security researchers who report product cybersecurity vulnerabilities in adherence to this policy:

 

Contributor
Organization Notification
Matt Waddell ivision CVE-2026-22620,
CVE-2026-22621,
CVE-2026-22622
Kazuma Matsumoto GMO Cybersecurity by IERAE, Inc. CVE-2026-22616,
CVE-2026-22617,
CVE-2026-22618,
CVE-2026-22619
Christian van der Meer - CVE-2026-22615
Luca Borzacchiello Nozomi Networks CVE-2026-22614
spacer
Contributor       
Organization Notification
Kazuma Matsumoto
GMO Cybersecurity by IERAE, Inc.
CVE-2025-67450
Mihkal Dunfjeld   CVE-2025-59886
Luca Borzacchiello
Nozomi Networks
CVE-2025-59890
Lang Khuong Duy (JuyLang)
Viettel IDC
CVE-2025-48396
Kazuma Matsumoto
GMO Cybersecurity by IERAE, Inc. CVE-2025-59889
Abdullah Waad  - -
Harry Sintonen Reversec CVE-2025-48393
CVE-2025-48394
spacer
Contributor       
Organization Notification
Joseph Yim Packetlabs CVE-2024-31415
spacer
Contributor       
Organization Notification
Manuel Stotz SySS GmbH CVE-2023-43776
CVE-2023-43777
- Communications Security Establishment, Canada.
CVE-2023-43775
Vangelis Stykas - ETN-VA-2023-1008
spacer
Contributor       
Organization Notification
Michael
- CVE-2022-33859
spacer
Contributor       
Organization Notification

Amir Preminger

Claroty

CVE-2021-23276
CVE-2021-23277
CVE-2021-23278
CVE-2021-23279
CVE-2021-23280
CVE-2021-23281

Micheal Heinzl via ICS-Cert

ICS-Cert

CVE-2021-23282
CVE-2021-23283
CVE-2021-23284
CVE-2021-23285
CVE-2021-23286

Andreas Finstad and Arthur Donkers

-

CVE-2021-23287
CVE-2021-23288

spacer
Contributor       
Organization Notification

Vishal Bharad

Independent

CVE-2020-6653

Yongjun Liu

NsFocus

CVE-2020-6654

Francis Provencher

Trend Micro Zero Day Initiative

CVE-2020-6655
CVE-2020-6656

Natnael Samson Trend Micro's ZDI

CVE-2020-10637

CVE-2020-10639

Ravjot Singh Samra   CVE-2020-6650
Sivathmican Sivakumaran Trend Micro's ZDI

CVE-2020-6651

CVE-2020-6652

spacer
Contributor                       Organization Notification
Emre Övünç   CVE-2018-12031
Tod Beardsly Rapid 7 CVE-2019-5625
spacer
Contributor                       Organization Notification
Ariele Caltabiano (kimiya) Trend Micro’s ZDI CVE-2018-7511
Ghirmay Desta Trend Micro’s ZDI CVE-2018-8847
spacer