Improper Input Validation in Eaton's Intelligent Power Manager (IPM) v 1.67 & prior on file name during configuration file import functionality allows attackers to perform command injection or code execution via specially crafted file names while uploading the configuration file in the application.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2020-27798 | Improper Input Validation in Eaton's Intelligent Power Manager (IPM) v 1.67 & prior on file name during configuration file import functionality allows attackers to perform command injection or code execution via specially crafted file names while uploading the configuration file in the application. |
Fixes
Solution
Update the software to latest version 1.68.
Workaround
Block ports 4679 & 4680 at enterprise network or home network where Intelligent Power Manager (IPM) software is installed and used.
References
History
No history.

Status: PUBLISHED
Assigner: Eaton
Published:
Updated: 2024-09-16T23:06:52.876Z
Reserved: 2020-01-09T00:00:00
Link: CVE-2020-6651

No data.

Status : Modified
Published: 2020-05-07T16:15:11.313
Modified: 2024-11-21T05:36:05.900
Link: CVE-2020-6651

No data.

No data.