At Eaton, cybersecurity is fundamental to delivering safe, reliable, and trusted products and solutions to our customers. We are committed to maintaining the security of our products and working with the security community, customers and others to responsibly address reported vulnerabilities because we believe that collaboration makes everyone safer.
This page sets out Eaton’s approach to coordinated vulnerability disclosure in accordance with applicable law, including the EU Cyber Resilience Act (CRA). You can also read Eaton’s full Coordinated Vulnerability Disclosure Policy for complete details on our reporting channels, handling process, safe harbor provisions, remediation approach, and disclosure practices.
What This Policy Covers
This policy applies to vulnerability reports submitted for the following Eaton products and services:
How to Report a Vulnerability
If you've discovered a potential security issue in an Eaton product or service, we want to hear from you. Vulnerability reports may be submitted by researchers, customers, CERTs, security intelligence agencies, authorized channel partners, or other third-party reporters (“Vulnerability Reporters”) through our designated reporting channels.
To report a vulnerability, please use one of the following channels:
What Happens After You Submit A Report
Once submitted, your report goes directly to our dedicated Product Security Incident Response Team (PSIRT), who will review and investigate the issue. You can expect to hear from us within two business days.
Eaton publicly discloses vulnerabilities in accordance with applicable law. High or Critical severity vulnerabilities (CVSS score 7.0 or above) are disclosed through a Vulnerability Advisory (for Eaton products) or Security Bulletin (for third-party components) on our notification page. For lower severity issues, Eaton will handle notifications on a case-by-case basis, typically with direct notice to customers or updates in version release notes. As a CVE Numbering Authority, Eaton will also assign a CVE number to High or Critical vulnerabilities in actively supported products.
Please note that Vulnerability Reporters are asked to respond to any follow-up questions within 30 days, after which the matter may be considered closed.
How We Protect Vulnerability Reporters (Safe Harbor)
Reporting a potential security issue takes trust, and we respect that. Eaton will not pursue legal action against reporters who:
Hall of Recognition
Eaton maintains a Hall of Recognition to recognize the contributions of Vulnerability Reporters, below. Eaton will acknowledge Vulnerability Reporters, with their consent, in applicable Vulnerability Advisories or Security Bulletins.
Eaton and the EU Cyber Resilience Act (“CRA”)
The CRA establishes cybersecurity requirements for connected products sold in the European Union. Many Eaton connected products sold in the EU are expected to be in scope. CRA obligations apply from September 2026 (vulnerability handling and incident reporting ) and December 2027 (full CE marking requirements).
Under the CRA, Eaton will:
For more information on Eaton’s CRA preparations, visit Eaton’s CRA page. For product-specific information, including SBOM and product security support information, please visit the respective product catalog page.
Public release of information relating to security vulnerabilities is on our Cybersecurity notifications page. This page is the central repository for Eaton product security advisories related to all Eaton electrical products. Customers are encouraged to monitor this portal for latest security advisories.
We intend to issue security advisories for validated vulnerabilities when a practical workaround or fix has been identified. There may be instances when an advisory is issued in the absence of a workaround. Because each security vulnerability is different, we may take alternative actions in connection with issuing security advisories.
Eaton does not guarantee that security advisories will be issued for any or all security issues that customers may consider significant or that advisories will be issued on any specific timeline.
Note: Eaton reserves the right to modify this policy at any time, in its sole discretion.
Eaton maintains a Hall of Recognition to duly recognize the contributions of security researchers who report product cybersecurity vulnerabilities in adherence to this policy:
| Contributor |
Organization | Notification |
|---|---|---|
| Matt Waddell | ivision | CVE-2026-22620, CVE-2026-22621, CVE-2026-22622 |
| Kazuma Matsumoto | GMO Cybersecurity by IERAE, Inc. | CVE-2026-22616, CVE-2026-22617, CVE-2026-22618, CVE-2026-22619 |
| Christian van der Meer | - | CVE-2026-22615 |
| Luca Borzacchiello | Nozomi Networks | CVE-2026-22614 |
| Contributor |
Organization | Notification |
| Kazuma Matsumoto |
GMO Cybersecurity by IERAE, Inc. |
CVE-2025-67450 |
| Mihkal Dunfjeld | CVE-2025-59886 | |
| Luca Borzacchiello |
Nozomi Networks |
CVE-2025-59890 |
| Lang Khuong Duy (JuyLang) |
Viettel IDC |
CVE-2025-48396 |
| Kazuma Matsumoto |
GMO Cybersecurity by IERAE, Inc. | CVE-2025-59889 |
| Abdullah Waad | - | - |
| Harry Sintonen | Reversec | CVE-2025-48393 CVE-2025-48394 |
| Contributor |
Organization | Notification |
| Joseph Yim | Packetlabs | CVE-2024-31415 |
| Contributor |
Organization | Notification |
| Manuel Stotz | SySS GmbH | CVE-2023-43776 CVE-2023-43777 |
| - | Communications Security Establishment, Canada. |
CVE-2023-43775 |
| Vangelis Stykas | - | ETN-VA-2023-1008 |
| Contributor |
Organization | Notification |
| Michael |
- | CVE-2022-33859 |
| Contributor |
Organization | Notification |
Amir Preminger |
Claroty |
CVE-2021-23276 |
Micheal Heinzl via ICS-Cert |
ICS-Cert |
CVE-2021-23282 |
Andreas Finstad and Arthur Donkers |
- |
| Contributor |
Organization | Notification |
Vishal Bharad |
Independent |
|
Yongjun Liu |
NsFocus |
|
Francis Provencher |
Trend Micro Zero Day Initiative |
|
| Natnael Samson | Trend Micro's ZDI | |
| Ravjot Singh Samra | CVE-2020-6650 | |
| Sivathmican Sivakumaran | Trend Micro's ZDI |
| Contributor | Organization | Notification |
| Emre Övünç | CVE-2018-12031 | |
| Tod Beardsly | Rapid 7 | CVE-2019-5625 |
| Contributor | Organization | Notification |
| Ariele Caltabiano (kimiya) | Trend Micro’s ZDI | CVE-2018-7511 |
| Ghirmay Desta | Trend Micro’s ZDI | CVE-2018-8847 |
View current notifications and sign up to receive alerts on vulnerabilities