Improper Input Validation in Eaton's Intelligent Power Manager (IPM) v 1.67 & prior on file name during configuration file import functionality allows attackers to perform command injection or code execution via specially crafted file names while uploading the configuration file in the application.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-27798 Improper Input Validation in Eaton's Intelligent Power Manager (IPM) v 1.67 & prior on file name during configuration file import functionality allows attackers to perform command injection or code execution via specially crafted file names while uploading the configuration file in the application.
Fixes

Solution

Update the software to latest version 1.68.


Workaround

Block ports 4679 & 4680 at enterprise network or home network where Intelligent Power Manager (IPM) software is installed and used.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Eaton

Published:

Updated: 2024-09-16T23:06:52.876Z

Reserved: 2020-01-09T00:00:00

Link: CVE-2020-6651

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-05-07T16:15:11.313

Modified: 2024-11-21T05:36:05.900

Link: CVE-2020-6651

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.