Insecure Encryption in Eaton's EasySoft Project Files Exposes Sensitive Information
CVE-2026-22614

6.1MEDIUM

Key Information:

Vendor

Eaton

Status
Vendor
CVE Published:
10 March 2026

What is CVE-2026-22614?

Eaton's EasySoft application features an insecure encryption method for project files, making these files vulnerable to brute force attacks. An attacker with access to the local host could potentially retrieve and manipulate sensitive data contained in these project files. Eaton has released a fix in the latest version of EasySoft, which is essential for users to implement in order to safeguard their sensitive information.

Affected Version(s)

EasySoft 0 < 8.4

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.